plugin

Apppresser Vulnerabilities

18 known security issues reported for the Apppresser WordPress plugin. Most recent disclosed Oct 30, 2025.

1 critical 4 high 4 medium

Running Apppresser on your site? Check whether your installed version is affected.

Scan your site free

AppPresser &#8211; Mobile App Framework [apppresser] < 4.5.1

unknown

[en] The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'myappp_verify' function in all versions up to, and including, 4.5.0. This makes it possible for unauthenticated attackers to extract sensitive data including plugin and...

Affected:
up to 4.5.1
Fixed in:
4.5.1
Disclosed:
Oct 30, 2025

CVE-2025-11881 on NVD →

AppPresser – Mobile App Framework <= 4.5.0 - Missing Authorization to Unauthenticated Limited Sensitive Information Exposure

medium

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'myappp_verify' function in all versions up to, and including, 4.5.0. This makes it possible for unauthenticated attackers to extract sensitive data including plugin and theme...

CVSS:
5.3
Affected:
up to 4.5.0
Fixed in:
4.5.1
Disclosed:
Oct 29, 2025

CVE-2025-11881 on NVD →

AppPresser – Mobile App Framework <= 4.4.10 - Unauthenticated Stored Cross-Site Scripting

high

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 4.4.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
7.2
Affected:
up to 4.4.10
Fixed in:
4.4.11
Disclosed:
Mar 12, 2025

CVE-2025-1561 on NVD →

AppPresser &#8211; Mobile App Framework [apppresser] < 4.4.7

unknown

[en] The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to the plugin not properly validating a user's password reset code prior to updating their password. This makes it possible for unauthentica...

Affected:
up to 4.4.7
Fixed in:
4.4.7
Disclosed:
Nov 26, 2024

CVE-2024-11024 on NVD →

AppPresser – Mobile App Framework <= 4.4.6 - Unauthenticated Privilege Escalation via Password Reset

critical

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to the plugin not properly validating a user's password reset code prior to updating their password. This makes it possible for unauthenticated a...

CVSS:
9.8
Affected:
up to 4.4.6
Fixed in:
4.4.7
Disclosed:
Nov 25, 2024

CVE-2024-11024 on NVD →

AppPresser &#8211; Mobile App Framework [apppresser] < 4.4.5

unknown

[en] The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() functions not having enough controls to prevent a successful brute force attack o...

Affected:
up to 4.4.5
Fixed in:
4.4.5
Disclosed:
Oct 16, 2024

CVE-2024-9305 on NVD →

AppPresser – Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTP

high

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() functions not having enough controls to prevent a successful brute force attack of the...

CVSS:
8.1
Affected:
up to 4.4.4
Fixed in:
4.4.5
Disclosed:
Oct 15, 2024

CVE-2024-9305 on NVD →

AppPresser &#8211; Mobile App Framework [apppresser] < 4.4.0

unknown

[en] The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an adm...

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
May 29, 2024

CVE-2024-4611 on NVD →

AppPresser <= 4.3.2 - Improper Missing Encryption Exception Handling to Authentication Bypass

high

The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administ...

CVSS:
8.1
Affected:
up to 4.3.2
Fixed in:
4.4.0
Disclosed:
May 28, 2024

CVE-2024-4611 on NVD →

AppPresser &#8211; Mobile App Framework [apppresser] < 4.3.1

unknown

[en] Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.

Affected:
up to 4.3.1
Fixed in:
4.3.1
Disclosed:
May 10, 2024

CVE-2024-32776 on NVD →

AppPresser <= 4.3.0 - Missing Authorization

medium

The AppPresser plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the toggle_logging_callback() function in versions up to, and including, 4.3.0. This makes it possible for unauthenticated attackers to enable and disable logging.

CVSS:
5.3
Affected:
up to 4.3.0
Fixed in:
4.3.1
Disclosed:
Apr 22, 2024

CVE-2024-32776 on NVD →

AppPresser &#8211; Mobile App Framework [apppresser] < 4.3.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.

Affected:
up to 4.3.1
Fixed in:
4.3.1
Disclosed:
Apr 15, 2024

CVE-2024-31374 on NVD →

AppPresser &#8211; Mobile App Framework [apppresser] < 4.3.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.

Affected:
up to 4.3.1
Fixed in:
4.3.1
Disclosed:
Apr 12, 2024

CVE-2024-31268 on NVD →

AppPresser <= 4.3.0 - Cross-Site Request Forgery via force_logging_off()

medium

The AppPresser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0. This is due to missing or incorrect nonce validation on the force_logging_off() function. This makes it possible for unauthenticated attackers to turn logging off via a forged request granted they ca...

CVSS:
4.3
Affected:
up to 4.3.0
Fixed in:
4.3.1
Disclosed:
Apr 10, 2024

CVE-2024-31374 on NVD →

AppPresser <= 4.3.0 - Cross-Site Request Forgery via toggle_logging_callback()

medium

The AppPresser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0. This is due to missing or incorrect nonce validation on the toggle_logging_callback() function. This makes it possible for unauthenticated attackers to toggle the logging functionality via a forged r...

CVSS:
4.3
Affected:
up to 4.3.0
Fixed in:
4.3.1
Disclosed:
Apr 5, 2024

CVE-2024-31268 on NVD →

AppPresser &#8211; Mobile App Framework [apppresser] < 4.3.0

unknown

[en] The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Nov 18, 2023

CVE-2023-4214 on NVD →

AppPresser <= 4.2.5 - Insecure Password Reset Mechanism

high

The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.

CVSS:
8.1
Affected:
up to 4.2.5
Fixed in:
4.3.0
Disclosed:
Nov 16, 2023

CVE-2023-4214 on NVD →

AppPresser &#8211; Mobile App Framework [apppresser] < 4.4.11

unknown
Affected:
up to 4.4.11
Fixed in:
4.4.11

CVE-2025-1561 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database