Privilege Escalation Vulnerability in App Builder Plugin for WordPress
CVE-2026-2375
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 March 2026
What is CVE-2026-2375?
The App Builder plugin for WordPress is susceptible to a privilege escalation issue affecting all versions up to and including 5.5.10. This vulnerability arises from the verify_role() function within the AuthTrails.php file, which incorrectly whitelists the wcfm_vendor role alongside more typical roles such as subscriber and customer. By directly assigning this role via the wp_insert_user() function, the standard WCFM Marketplace vendor approval process is bypassed. This flaw allows unauthenticated attackers to exploit the /wp-json/app-builder/v1/register REST API endpoint to register as a wcfm_vendor, granting them immediate vendor-level privileges, including product management and order access, on sites utilizing the WCFM Marketplace.
Affected Version(s)
App Builder β Create Native Android & iOS Apps On The Flight 0 <= 5.5.10