CVE-2026-13736: NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API
Published Aug 21, 2026
·Updated
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.
Affected Software
1 affected component
WordPress plugin - WildApricotPress Add-on (Member Directory)<=1.0.0
Event History
Aug 21, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Sites using the WildApricotPress Add-on Member Directory plugin through version 1.0.0 are exposed when member email addresses or phone numbers are configured as visible to members only.
2
What does an attacker need to exploit it?
An attacker only needs unauthenticated access to the affected REST API route. No member account or other authentication is required.
3
What information can be disclosed?
Anonymous visitors can obtain member email addresses and phone numbers that the site configuration intends to restrict to members.