plugin

Appmax Vulnerabilities

1 known security issue reported for the Appmax WordPress plugin. Most recent disclosed Mar 20, 2026.

1 medium

Running Appmax on your site? Check whether your installed version is affected.

Scan your site free

Appmax <= 1.0.3 - Missing Authorization to Order Status Manipulation and Arbitrary Order Creation via Webhook Endpoint

medium

The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. This is due to the plugin registering a public REST API webhook endpoint at /webhook-system without implementing webhook signature validation, secret verification, or any mechanism to authenticate tha...

CVSS:
5.3
Affected:
up to 1.0.3
Fix:
No patched version reported
Disclosed:
Mar 20, 2026

CVE-2026-3641 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database