plugin

Stacks Mobile App Builder Vulnerabilities

6 known security issues reported for the Stacks Mobile App Builder WordPress plugin. Most recent disclosed Nov 4, 2024.

2 critical 1 medium

Running Stacks Mobile App Builder on your site? Check whether your installed version is affected.

Scan your site free

Stacks Mobile App Builder &#8211; The most powerful Mobile Applications Drag and Drop builder [stacks-mobile-app-builder] <= 5.2.3 (unfixed + closed)

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.

Affected:
up to 5.2.3
Fix:
No patched version reported
Disclosed:
Nov 4, 2024

CVE-2024-50528 on NVD →

Stacks Mobile App Builder &#8211; The most powerful Mobile Applications Drag and Drop builder [stacks-mobile-app-builder] <= 5.2.3 (unfixed + closed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.

Affected:
up to 5.2.3
Fix:
No patched version reported
Disclosed:
Nov 4, 2024

CVE-2024-50527 on NVD →

Stacks Mobile App Builder <= 5.2.3 - Unauthenticated Arbitrary File Upload

critical

The Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 5.2.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the...

CVSS:
9.8
Affected:
up to 5.2.3
Fix:
No patched version reported
Disclosed:
Oct 30, 2024

CVE-2024-50527 on NVD →

Stacks Mobile App Builder <= 5.2.3 - Unauthenticated Sensitive Information Disclosure

medium

The Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 5.2.3
Fix:
No patched version reported
Disclosed:
Oct 30, 2024

CVE-2024-50528 on NVD →

Stacks Mobile App Builder &#8211; The most powerful Mobile Applications Drag and Drop builder [stacks-mobile-app-builder] <= 5.2.3 (unfixed + closed)

unknown

[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.

Affected:
up to 5.2.3
Fix:
No patched version reported
Disclosed:
Oct 28, 2024

CVE-2024-50477 on NVD →

Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover

critical

The Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.2.3. This is due to the plugin not properly verifying a user's identity prior to authenticating them via the receive_request_che...

CVSS:
9.8
Affected:
up to 5.2.3
Fix:
No patched version reported
Disclosed:
Oct 25, 2024

CVE-2024-50477 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database