CVE-2026-2375 PUBLISHED

App Builder – Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' Parameter

Assigner: Wordfence
Reserved: 11.02.2026 Published: 21.03.2026 Updated: 21.03.2026

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the verify_role() function in AuthTrails.php explicitly whitelisting the wcfm_vendor role alongside subscriber and customer, and assigning it directly via wp_insert_user() without integrating with WCFM Marketplace's vendor approval workflow. This makes it possible for unauthenticated attackers to register an account with the wcfm_vendor role by supplying the role parameter in the /wp-json/app-builder/v1/register REST API endpoint, bypassing the standard WCFM vendor approval process and immediately gaining vendor-level privileges (product management, order access, store management) on sites where WCFM Marketplace is active.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 6.5

Product Status

Vendor appcheap
Product App Builder – Create Native Android & iOS Apps On The Flight
Versions Default: unaffected
  • affected from * to 5.5.10 (incl.)

Credits

  • Gibran Abdillah finder

References

Problem Types

  • CWE-269 Improper Privilege Management CWE