Tag
medium
advisory
Unauthenticated PII Disclosure in NewPath WildApricotPress WordPress Plugin
1 rule 2 TTPs 1 CVECVE-2026-13736 allows unauthenticated attackers to scrape sensitive member PII from the NewPath WildApricotPress Member Directory WordPress plugin via an insecure REST API endpoint.
WildApricotPress Add-on – Member Directory
wordpress
information-disclosure
rest-api
pii
1r
2t
1c
high
advisory
Craft CMS GraphQL Address Resolver Missing Authorization Allows PII Disclosure
2 rules 1 TTPA missing authorization check in the GraphQL Address element resolver of Craft CMS Pro allows a GraphQL API token scoped to a low-privilege user group to read all addresses in the system, including those belonging to users in groups the token is not authorized to access, exposing personally identifiable information (PII).
cms +2
craftcms
graphql
pii
disclosure
2r
1t