CVE-2026-13736
NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API
- Published
- Aug 21, 2026
- Updated
- Aug 21, 2026
- Assigning CNA
- WPScan
- Evidence observed
- Aug 24, 2026
Primary CVSS
cvelist_adp · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NSummary
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.
Sources
Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including root-cause analysis, PoC code, and remediation guidance.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.