CVE-2026-3651 PUBLISHED

Build App Online <= 1.0.23 - Missing Authorization to Arbitrary Post Author Modification via 'build-app-online-update-vendor-product' AJAX Action

Assigner: Wordfence
Reserved: 06.03.2026 Published: 21.03.2026 Updated: 21.03.2026

The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. This is due to the plugin registering the 'build-app-online-update-vendor-product' AJAX action via wp_ajax_nopriv_ without proper authentication checks, capability verification, or nonce validation in the update_vendor_product() function. The function accepts a user-supplied post ID from the request and calls wp_update_post() to modify the post_author field without validating whether the user has permission to modify the specified post. This makes it possible for unauthenticated attackers to modify the post_author of arbitrary posts to 0 (orphaning posts from their legitimate authors), or for authenticated attackers to claim ownership of any post by setting themselves as the author.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor hakeemnala
Product Build App Online
Versions Default: unaffected
  • affected from * to 1.0.23 (incl.)

Credits

  • Ronnachai Sretawat Na Ayutaya finder
  • Ronnachai Chaipha finder

References

Problem Types

  • CWE-862 Missing Authorization CWE