VYPR
Medium severity5.3NVD Advisory· Published Aug 21, 2026· Updated Aug 26, 2026

CVE-2026-13736

CVE-2026-13736

Description

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

2