CyberRota Analysis
AI-GeneratedThe NewPath WildApricotPress Add-on for WordPress versions up to 1.0.0 is vulnerable due to inadequate enforcement of member privacy settings on an unauthenticated REST route, exposing sensitive member information such as email addresses and phone numbers to unauthorized users. This vulnerability poses a significant risk to user data privacy and could lead to potential misuse of personal information. WordPress site administrators using this plugin should prioritize immediate updates to safeguard member data.
Original NVD Description
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.