{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/newpath/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":5.3,"id":"CVE-2026-13736"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WildApricotPress Add-on – Member Directory (1.0.0)"],"_cs_severities":["medium"],"_cs_tags":["wordpress","information-disclosure","rest-api","pii"],"_cs_type":"advisory","_cs_vendors":["NewPath"],"content_html":"\u003cp\u003eCVE-2026-13736 is an unauthenticated information disclosure vulnerability in the NewPath WildApricotPress Add-on - Member Directory for WordPress (version 1.0.0 and below). The plugin registers a custom REST API endpoint, \u003ccode\u003e/wp-json/newpath-wap/v1/directory\u003c/code\u003e, which is intended to display member information. However, the endpoint defines its \u003ccode\u003epermission_callback\u003c/code\u003e as \u003ccode\u003e__return_true\u003c/code\u003e, explicitly allowing unauthenticated access. Furthermore, the backend implementation fails to apply field-level privacy filtering, serializing raw member objects that include sensitive PII such as email addresses, physical addresses, and phone numbers. An attacker can exploit this flaw by sending a standard HTTP GET request to the vulnerable endpoint, potentially harvesting the entire member database. This vulnerability poses a significant risk to the privacy of members associated with organizations utilizing this plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify WordPress sites running the NewPath WildApricotPress Add-on.\u003c/li\u003e\n\u003cli\u003eAttacker confirms the presence of the vulnerable endpoint at \u003ccode\u003e/wp-json/newpath-wap/v1/directory\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker sends an unauthenticated HTTP GET request to the target REST endpoint.\u003c/li\u003e\n\u003cli\u003eThe WordPress REST server processes the request, bypassing authentication due to the insecure \u003ccode\u003epermission_callback\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe plugin code executes \u003ccode\u003enewpath_wap_get_member_directory\u003c/code\u003e to fetch raw data.\u003c/li\u003e\n\u003cli\u003eThe backend retrieves the full member record set without checking user session privileges.\u003c/li\u003e\n\u003cli\u003eThe server responds with a JSON payload containing raw PII fields.\u003c/li\u003e\n\u003cli\u003eAttacker parses the JSON output to collect and store the scraped PII.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized mass exfiltration of sensitive member information, including names, personal emails, physical addresses, and contact phone numbers. This can lead to increased targeted phishing campaigns against the membership base, potential GDPR or other regulatory compliance violations for the host organization, and loss of trust in the platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the \u003ccode\u003eNewPath WildApricotPress Add-on - Member Directory\u003c/code\u003e plugin to the latest version, which enforces proper authentication and data serialization.\u003c/li\u003e\n\u003cli\u003eImplement the Sigma detection rule below to identify unauthorized access attempts to the vulnerable REST endpoint.\u003c/li\u003e\n\u003cli\u003eIf an update is not immediately feasible, use a web application firewall or server configuration to block unauthenticated requests to \u003ccode\u003e/wp-json/newpath-wap/v1/directory\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-22T19:49:36Z","date_published":"2026-08-22T19:49:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-13736/","summary":"CVE-2026-13736 allows unauthenticated attackers to scrape sensitive member PII from the NewPath WildApricotPress Member Directory WordPress plugin via an insecure REST API endpoint.","title":"Unauthenticated PII Disclosure in NewPath WildApricotPress WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-13736/"}],"language":"en","title":"CraftedSignal Threat Feed - NewPath","version":"https://jsonfeed.org/version/1.1"}