Product
CVE-2026-13736 allows unauthenticated attackers to scrape sensitive member PII from the NewPath WildApricotPress Member Directory WordPress plugin via an insecure REST API endpoint.