The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-21 07:16
Updated : 2026-08-26 16:30
NVD link : CVE-2026-13736
Mitre link : CVE-2026-13736
CVE.ORG link : CVE-2026-13736
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
