plugin

Build App Online Vulnerabilities

18 known security issues reported for the Build App Online WordPress plugin. Most recent disclosed Mar 20, 2026.

3 critical 3 high 3 medium

Running Build App Online on your site? Check whether your installed version is affected.

Scan your site free

Build App Online <= 1.0.23 - Missing Authorization to Arbitrary Post Author Modification via 'build-app-online-update-vendor-product' AJAX Action

medium

The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. This is due to the plugin registering the 'build-app-online-update-vendor-product' AJAX action via wp_ajax_nopriv_ without proper authentication checks, capability verification, or nonce validati...

CVSS:
5.3
Affected:
up to 1.0.23
Fix:
No patched version reported
Disclosed:
Mar 20, 2026

CVE-2026-3651 on NVD →

Build App Online <= 1.0.23 - Cross-Site Request Forgery

medium

The Build App Online plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.23. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site adm...

CVSS:
4.3
Affected:
up to 1.0.23
Fix:
No patched version reported
Disclosed:
Aug 14, 2025

CVE-2025-53249 on NVD →

Build App Online [build-app-online] <= 1.0.23 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online allows Cross Site Request Forgery. This issue affects Build App Online: from n/a through 1.0.23.

Affected:
up to 1.0.23
Fix:
No patched version reported
Disclosed:
Aug 14, 2025

CVE-2025-53249 on NVD →

Build App Online [build-app-online] <= 1.0.23 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hakeemnala Build App Online allows PHP Local File Inclusion. This issue affects Build App Online: from n/a through 1.0.23.

Affected:
up to 1.0.23
Fix:
No patched version reported
Disclosed:
Apr 11, 2025

CVE-2025-32577 on NVD →

Build App Online <= 1.0.23 - Unauthenticated Local File Inclusion

critical

The Build App Online plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.23. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access co...

CVSS:
9.8
Affected:
up to 1.0.23
Fix:
No patched version reported
Disclosed:
Apr 9, 2025

CVE-2025-32577 on NVD →

Build App Online [build-app-online] <= 1.0.23 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Abdul Hakeem Build App Online allows PHP Local File Inclusion.This issue affects Build App Online: from n/a through 1.0.23.

Affected:
up to 1.0.23
Fix:
No patched version reported
Disclosed:
Jan 7, 2025

CVE-2024-49649 on NVD →

Build App Online <= 1.0.23 - Unauthenticated Local File Inclusion

high

The Build App Online plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.23. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass acces...

CVSS:
8.1
Affected:
up to 1.0.23
Fix:
No patched version reported
Disclosed:
Jan 6, 2025

CVE-2024-49649 on NVD →

Build App Online [build-app-online] <= 1.0.23 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Abdul Hakeem Build App Online allows Cross Site Request Forgery.This issue affects Build App Online: from n/a through 1.0.22.

Affected:
up to 1.0.23
Fix:
No patched version reported
Disclosed:
Dec 2, 2024

CVE-2024-53751 on NVD →

Build App Online <= 1.0.22 - Cross-Site Request Forgery

medium

The Build App Online plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.22. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...

CVSS:
4.3
Affected:
up to 1.0.22
Fix:
No patched version reported
Disclosed:
Nov 28, 2024

CVE-2024-53751 on NVD →

Build App Online [build-app-online] < 1.0.23

unknown

[en] The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.

Affected:
up to 1.0.23
Fixed in:
1.0.23
Disclosed:
Jun 11, 2024

CVE-2023-7264 on NVD →

Build App Online [build-app-online] <= 1.0.21 (unfixed)

unknown
Affected:
up to 1.0.21
Fix:
No patched version reported
Disclosed:
May 18, 2024

CVE-2024-3658 on NVD →

Build App Online [build-app-online] < 1.0.21

unknown

[en] Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

Affected:
up to 1.0.21
Fixed in:
1.0.21
Disclosed:
May 17, 2024

CVE-2023-51479 on NVD →

Build App Online [build-app-online] < 1.0.22

unknown

[en] Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

Affected:
up to 1.0.22
Fixed in:
1.0.22
Disclosed:
Apr 25, 2024

CVE-2023-51478 on NVD →

Build App Online <= 1.0.21 - Authentication Bypass via Header

critical

The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.21. This is due to missing authentication checking in the 'set_user_cart' function with the 'user_id' header value. This makes it possible for unauthenticated attackers to log in as any existing user o...

CVSS:
9.8
Affected:
up to 1.0.21
Fixed in:
1.0.22
Disclosed:
Dec 27, 2023

CVE-2023-51478 on NVD →

Build App Online <= 1.0.20 - Missing Authorization Authenticated(Subscriber+) Arbitrary Options Update

high

The Build App Online plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_user_meta' and 'update_user_meta_value' functions in all versions up to, and including, 1.0.20. This makes it possible for authenticated attackers, with subscriber access and ab...

CVSS:
8.8
Affected:
up to 1.0.20
Fixed in:
1.0.21
Disclosed:
Dec 27, 2023

CVE-2023-51479 on NVD →

Build App Online <= 1.0.22 - Account Takeover via Weak Password Reset Mechanism

high

The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.

CVSS:
8.1
Affected:
up to 1.0.22
Fixed in:
1.0.23
Disclosed:
Dec 27, 2023

CVE-2023-7264 on NVD →

Build App Online [build-app-online] < 1.0.19

unknown

[en] The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Affected:
up to 1.0.19
Fixed in:
1.0.19
Disclosed:
Jan 2, 2023

CVE-2022-3241 on NVD →

Build App Online <= 1.0.18 - Unauthenticated SQL Injection

critical

The Build App Online plugin for WordPress is vulnerable to SQL Injection via an AJAX action available to unprivileged users in versions up to, and including, 1.0.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauth...

CVSS:
9.8
Affected:
up to 1.0.18
Fixed in:
1.0.19
Disclosed:
Dec 6, 2022

CVE-2022-3241 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database