WordPress Plugin CVE-2026-13736 Exposes Member PII to Unauthenticated Users
A medium-severity vulnerability, CVE-2026-13736, has been identified in the NewPath WildApricotPress Member Directory WordPress plugin up to and including version 1.0.0. Discovered by cybersecurity researcher Huynh Kien Minh, the flaw stems from a publicly accessible REST API endpoint that lacks proper access controls. Because the backend serializes raw member data without filtering restricted fields, unauthenticated visitors can retrieve private emails, phone numbers, and other members-only profile attributes. The vulnerability carries a CVSS 3.1 score of 5.3 (Medium) and is classified under CWE-284 and CWE-200, relating to improper access control and information exposure. Minh recommends immediate remediation through REST endpoint permission hardening, field-level privacy checks, and sanitization of JSON API responses.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in