Build App Online <= 1.0.23 - Missing Authorization to Arbitrary Post Author Modification via 'build-app-online-update-vendor-product' AJAX Action
medium
The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. This is due to the plugin registering the 'build-app-online-update-vendor-product' AJAX action via wp_ajax_nopriv_ without proper authentication checks, capability verification, or nonce validati...
- CVSS:
- 5.3
- Affected:
- up to 1.0.23
- Fix:
- No patched version reported
- Disclosed:
- Mar 20, 2026
CVE-2026-3651 on NVD →
Build App Online <= 1.0.23 - Cross-Site Request Forgery
medium
The Build App Online plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.23. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site adm...
- CVSS:
- 4.3
- Affected:
- up to 1.0.23
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2025
CVE-2025-53249 on NVD →
Build App Online [build-app-online] <= 1.0.23 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online allows Cross Site Request Forgery. This issue affects Build App Online: from n/a through 1.0.23.
- Affected:
- up to 1.0.23
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2025
CVE-2025-53249 on NVD →
Build App Online [build-app-online] <= 1.0.23 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hakeemnala Build App Online allows PHP Local File Inclusion. This issue affects Build App Online: from n/a through 1.0.23.
- Affected:
- up to 1.0.23
- Fix:
- No patched version reported
- Disclosed:
- Apr 11, 2025
CVE-2025-32577 on NVD →
Build App Online <= 1.0.23 - Unauthenticated Local File Inclusion
critical
The Build App Online plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.23. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access co...
- CVSS:
- 9.8
- Affected:
- up to 1.0.23
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2025
CVE-2025-32577 on NVD →
Build App Online [build-app-online] <= 1.0.23 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Abdul Hakeem Build App Online allows PHP Local File Inclusion.This issue affects Build App Online: from n/a through 1.0.23.
- Affected:
- up to 1.0.23
- Fix:
- No patched version reported
- Disclosed:
- Jan 7, 2025
CVE-2024-49649 on NVD →
Build App Online <= 1.0.23 - Unauthenticated Local File Inclusion
high
The Build App Online plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.23. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass acces...
- CVSS:
- 8.1
- Affected:
- up to 1.0.23
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2025
CVE-2024-49649 on NVD →
Build App Online [build-app-online] <= 1.0.23 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Abdul Hakeem Build App Online allows Cross Site Request Forgery.This issue affects Build App Online: from n/a through 1.0.22.
- Affected:
- up to 1.0.23
- Fix:
- No patched version reported
- Disclosed:
- Dec 2, 2024
CVE-2024-53751 on NVD →
Build App Online <= 1.0.22 - Cross-Site Request Forgery
medium
The Build App Online plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.22. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 1.0.22
- Fix:
- No patched version reported
- Disclosed:
- Nov 28, 2024
CVE-2024-53751 on NVD →
Build App Online [build-app-online] < 1.0.23
unknown
[en] The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.
- Affected:
- up to 1.0.23
- Fixed in:
- 1.0.23
- Disclosed:
- Jun 11, 2024
CVE-2023-7264 on NVD →
Build App Online [build-app-online] <= 1.0.21 (unfixed)
unknown
- Affected:
- up to 1.0.21
- Fix:
- No patched version reported
- Disclosed:
- May 18, 2024
CVE-2024-3658 on NVD →
Build App Online [build-app-online] < 1.0.21
unknown
[en] Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.
- Affected:
- up to 1.0.21
- Fixed in:
- 1.0.21
- Disclosed:
- May 17, 2024
CVE-2023-51479 on NVD →
Build App Online [build-app-online] < 1.0.22
unknown
[en] Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.
- Affected:
- up to 1.0.22
- Fixed in:
- 1.0.22
- Disclosed:
- Apr 25, 2024
CVE-2023-51478 on NVD →
Build App Online <= 1.0.21 - Authentication Bypass via Header
critical
The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.21. This is due to missing authentication checking in the 'set_user_cart' function with the 'user_id' header value. This makes it possible for unauthenticated attackers to log in as any existing user o...
- CVSS:
- 9.8
- Affected:
- up to 1.0.21
- Fixed in:
- 1.0.22
- Disclosed:
- Dec 27, 2023
CVE-2023-51478 on NVD →
Build App Online <= 1.0.20 - Missing Authorization Authenticated(Subscriber+) Arbitrary Options Update
high
The Build App Online plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_user_meta' and 'update_user_meta_value' functions in all versions up to, and including, 1.0.20. This makes it possible for authenticated attackers, with subscriber access and ab...
- CVSS:
- 8.8
- Affected:
- up to 1.0.20
- Fixed in:
- 1.0.21
- Disclosed:
- Dec 27, 2023
CVE-2023-51479 on NVD →
Build App Online <= 1.0.22 - Account Takeover via Weak Password Reset Mechanism
high
The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.
- CVSS:
- 8.1
- Affected:
- up to 1.0.22
- Fixed in:
- 1.0.23
- Disclosed:
- Dec 27, 2023
CVE-2023-7264 on NVD →
Build App Online [build-app-online] < 1.0.19
unknown
[en] The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
- Affected:
- up to 1.0.19
- Fixed in:
- 1.0.19
- Disclosed:
- Jan 2, 2023
CVE-2022-3241 on NVD →
Build App Online <= 1.0.18 - Unauthenticated SQL Injection
critical
The Build App Online plugin for WordPress is vulnerable to SQL Injection via an AJAX action available to unprivileged users in versions up to, and including, 1.0.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauth...
- CVSS:
- 9.8
- Affected:
- up to 1.0.18
- Fixed in:
- 1.0.19
- Disclosed:
- Dec 6, 2022
CVE-2022-3241 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database