Privilege Escalation Vulnerability in App Builder Plugin for WordPress
CVE-2026-2375

6.5MEDIUM

What is CVE-2026-2375?

The App Builder plugin for WordPress is susceptible to a privilege escalation issue affecting all versions up to and including 5.5.10. This vulnerability arises from the verify_role() function within the AuthTrails.php file, which incorrectly whitelists the wcfm_vendor role alongside more typical roles such as subscriber and customer. By directly assigning this role via the wp_insert_user() function, the standard WCFM Marketplace vendor approval process is bypassed. This flaw allows unauthenticated attackers to exploit the /wp-json/app-builder/v1/register REST API endpoint to register as a wcfm_vendor, granting them immediate vendor-level privileges, including product management and order access, on sites utilizing the WCFM Marketplace.

Affected Version(s)

App Builder – Create Native Android & iOS Apps On The Flight 0 <= 5.5.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gibran Abdillah
.