Insecure Direct Object Reference in App Builder Plugin for WordPress
CVE-2026-7638
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 May 2026
What is CVE-2026-7638?
The App Builder β Create Native Android & iOS Apps On The Flight plugin for WordPress is susceptible to an Insecure Direct Object Reference due to inadequate authorization checks in the upload_avatar() function. An attacker can manipulate the user_id parameter in the POST request to modify user meta data without proper validation. This flaw allows authenticated users with Subscriber-level accounts or higher to alter the avatar of any user, including administrators, through the vulnerable endpoint. The issue exists in all versions up to and including 5.6.0 and poses a significant risk that could lead to unauthorized account alterations.
Affected Version(s)
App Builder β Create Native Android & iOS Apps On The Flight 0 <= 5.6.0