VYPR
Medium severity6.5NVD Advisory· Published Mar 21, 2026· Updated Apr 22, 2026

CVE-2026-2375

CVE-2026-2375

Description

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the verify_role() function in AuthTrails.php explicitly whitelisting the wcfm_vendor role alongside subscriber and customer, and assigning it directly via wp_insert_user() without integrating with WCFM Marketplace's vendor approval workflow. This makes it possible for unauthenticated attackers to register an account with the wcfm_vendor role by supplying the role parameter in the /wp-json/app-builder/v1/register REST API endpoint, bypassing the standard WCFM vendor approval process and immediately gaining vendor-level privileges (product management, order access, store management) on sites where WCFM Marketplace is active.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.