CVE-2026-13736Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-21: 3Technical Details · 2026-08-21: 308-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13736 NewPath WildApricotPress Add-on Exposes Member Data via Unauthenticated ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13736 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE-2026-13736, a new data‑exposure vulnerability in the NewPath WildApricotPress add‑on that allows unauthenticated access to member data, without providing any PoC, exploit code, or patch information.

    0000094
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13736 The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymo… https://www.cve.org/CVERecord?id=CVE-2026-13736 ----- Traducción: CVE-2026-13736 El … http://infoflow.cloud`

    Post summary

    The tweet shares a preliminary CVE disclosure for CVE‑2026‑13736, describing a privacy enforcement flaw in the WildApricotPress WordPress plugin's REST route but provides no PoC, exploit code, patch, or evidence of real‑world exploitation.

    0000023
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13736 The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymo… https://www.cve.org/CVERecord?id=CVE-2026-13736

    Post summary

    The vulnerability CVE‑2026‑13736 impacts the NewPath WildApricotPress add‑on for WordPress, enabling unauthenticated access to member‑only fields via an unsecured REST route. No proof‑of‑concept, exploit, or patch is referenced.

    00000808
    58.0K followersView on X

Explore more