WordPress Plugin Vulnerabilities

NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API

Description

The plugin does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Huynh Kien Minh
Submitter
Huynh Kien Minh
Verified
Yes

Timeline

Publicly Published
2026-08-18 (about 24 days ago)
Added
2026-08-11 (about 1 month ago)
Last Updated
2026-08-11 (about 1 month ago)

Other