SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-13736

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The NewPath WildApricotPress Add-on for WordPress versions up to 1.0.0 is vulnerable due to inadequate enforcement of member privacy settings on an unauthenticated REST route, exposing sensitive member information such as email addresses and phone numbers to unauthorized users. This vulnerability poses a significant risk to user data privacy and could lead to potential misuse of personal information. WordPress site administrators using this plugin should prioritize immediate updates to safeguard member data.

CVE
CVE-2026-13736
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%
WordPress

Original NVD Description

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.