Review
NewPath
CVE published 2026-08-21
CVE-2026-13736
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only. This vulnerability affects users of the plugin who have sensitive member information. The issue is related to the plugin's handling [truncated]