PatchSiren cyber security CVE debrief
CVE-2026-13736 NewPath CVE debrief
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only. This vulnerability affects users of the plugin who have sensitive member information. The issue is related to the plugin's handling of REST routes and member data privacy. Defenders should verify the plugin version, review member information exposure, and monitor for potential exploitation attempts. The CVE record was published on 2026-08-21T07:16:24.323Z and has not been modified since then. Further investigation is recommended to fully understand the vulnerability.
- Vendor
- NewPath
- Product
- WildApricotPress Add‑on
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Users of the NewPath WildApricotPress Add-on WordPress plugin, especially those with sensitive member information, should be aware of this vulnerability and take necessary actions to protect their member data. This includes reviewing the plugin version, restricting access to sensitive information, and monitoring for potential exploitation attempts. Additionally, operators, platform administrators, and security teams may need to review and update their security measures to mitigate the impact of this vulnerability.
Technical summary
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only. This vulnerability affects users of the plugin who have sensitive member information. The issue is related to the plugin's handling of REST routes and member data privacy.
Defensive priority
Members-only field privacy not enforced on unauthenticated REST route.
Recommended defensive actions
- Verify the NewPath WildApricotPress Add-on WordPress plugin version and update if necessary.
- Restrict access to sensitive member information.
- Monitor for potential exploitation attempts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
CVE-2026-13736 details are based on limited information from the CVE and NVD records. Further investigation is recommended to fully understand the vulnerability. The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only. Defenders should verify the plugin version, review member information exposure, and monitor for potential exploitation attempts.
Official resources
-
CVE-2026-13736 CVE record
CVE.org
-
CVE-2026-13736 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T07:16:24.323Z and has not been modified since then.