plugin

App Builder Vulnerabilities

12 known security issues reported for the App Builder WordPress plugin. Most recent disclosed May 1, 2026.

1 high 6 medium

Running App Builder on your site? Check whether your installed version is affected.

Scan your site free

App Builder <= 5.5.10 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Avatar Modification via 'user_id' Parameter

medium

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization validation in the `upload_avatar()` function, which accepts an attacker-controlled `user_id` parameter...

CVSS:
5.3
Affected:
up to 5.6.0
Fix:
No patched version reported
Disclosed:
May 1, 2026

CVE-2026-7638 on NVD →

App Builder – Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' Parameter

medium

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the `verify_role()` function in `AuthTrails.php` explicitly whitelisting the `wcfm_vendor` role alongside `subscriber` and `customer`,...

CVSS:
6.5
Affected:
up to 5.5.10
Fix:
No patched version reported
Disclosed:
Mar 20, 2026

CVE-2026-2375 on NVD →

App Builder &#8211; Create Native Android &amp; iOS Apps On The Flight [app-builder] <= 5.5.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in App Cheap App Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects App Builder: from n/a through 5.5.3.

Affected:
up to 5.5.3
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-49989 on NVD →

App Builder <= 5.5.7 - Missing Authorization

medium

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.5.7
Fixed in:
5.5.8
Disclosed:
Jun 19, 2025

CVE-2025-49989 on NVD →

App Builder &#8211; Create Native Android &amp; iOS Apps On The Flight [app-builder] < 5.3.8

unknown

[en] The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_password() functions not having enough controls to prevent a succe...

Affected:
up to 5.3.8
Fixed in:
5.3.8
Disclosed:
Oct 25, 2024

CVE-2024-9302 on NVD →

App Builder – Create Native Android & iOS Apps On The Flight <= 5.3.7 - Privilege Escalation and Account Takeover via Weak OTP

high

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_password() functions not having enough controls to prevent a successful...

CVSS:
8.1
Affected:
up to 5.3.7
Fixed in:
5.3.8
Disclosed:
Oct 24, 2024

CVE-2024-9302 on NVD →

App Builder &#8211; Create Native Android &amp; iOS Apps On The Flight [app-builder] < 4.3.4

unknown

[en] The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Injection via the ‘app-builder-search’ parameter in all versions up to, and including, 4.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exist...

Affected:
up to 4.3.4
Fixed in:
4.3.4
Disclosed:
Aug 21, 2024

CVE-2024-7651 on NVD →

App Builder – Create Native Android & iOS Apps On The Flight <= 4.3.3 - Unauthenticated Limited SQL Injection via app-builder-search

medium

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Injection via the ‘app-builder-search’ parameter in all versions up to, and including, 4.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing S...

CVSS:
5.6
Affected:
up to 4.3.3
Fixed in:
4.3.4
Disclosed:
Aug 20, 2024

CVE-2024-7651 on NVD →

App Builder &#8211; Create Native Android &amp; iOS Apps On The Flight [app-builder] < 3.8.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Appcheap.Io App Builder allows Stored XSS.This issue affects App Builder: from n/a through 3.8.8.

Affected:
up to 3.8.9
Fixed in:
3.8.9
Disclosed:
Apr 18, 2024

CVE-2024-32565 on NVD →

App Builder <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut...

CVSS:
6.4
Affected:
up to 3.8.8
Fixed in:
3.8.9
Disclosed:
Apr 16, 2024

CVE-2024-32565 on NVD →

App Builder &#8211; Create Native Android &amp; iOS Apps On The Flight [app-builder] < 3.8.8

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7.

Affected:
up to 3.8.8
Fixed in:
3.8.8
Disclosed:
Apr 10, 2024

CVE-2024-31282 on NVD →

App Builder <= 3.8.7 - Open Redirection

medium

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.8.7. This is due to insufficient validation on the redirect url supplied via the 'url' parameter. This makes it possible for unauthenticated attackers to redirect...

CVSS:
5.4
Affected:
up to 3.8.7
Fixed in:
3.8.8
Disclosed:
Apr 5, 2024

CVE-2024-31282 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database