Junglewise Threat Intelligence

CVE-2026-13736: NewPath WildApricotPress Add-on access control bypass in REST API

CVE-2026-13736 · Severity: medium · CVSS 5.3 · Published 2026-08-21

Executive brief

The NewPath WildApricotPress Add-on is a WordPress plugin that integrates member directory functionality with WildApricot. The plugin fails to enforce access restrictions on its REST API endpoint, allowing anyone on the internet to retrieve member email addresses and phone numbers that should only be visible to logged-in members. This exposes sensitive personal information and can facilitate targeted phishing, spam, or social engineering attacks.

Technical details

The vulnerability is a broken access control flaw in the WildApricotPress Add-on's REST API endpoint (/wp-json/wawp/v1/profiles/). The plugin does not validate user authentication or authorization before returning member profile data marked as "members-only," allowing unauthenticated HTTP requests to retrieve email addresses and phone numbers that should be restricted. Attackers can enumerate members by incrementing sequential member IDs in unauthenticated requests. No authentication, nonce, or special preconditions are required; the attack requires only network access to the WordPress site. The vulnerability affects versions through 1.0.0 and no known patch has been released as of the advisory publication date.

Affected products

  • NewPath WildApricotPress Add-on through 1.0.0

Timeline

  • 2026-08-18: disclosed
  • 2026-08-21: advisory

References