CVE-2026-7638
- EPSS 0.31%
- Veröffentlicht 02.05.2026 03:36:42
- Zuletzt bearbeitet 05.05.2026 19:17:22
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization validation in the `upload_avatar(...
CVE-2026-2375
- EPSS 0.28%
- Veröffentlicht 21.03.2026 03:26:32
- Zuletzt bearbeitet 22.04.2026 21:32:08
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the `verify_role()` function in `AuthTrails.php` explicitly white...
CVE-2025-49989
- EPSS 0.27%
- Veröffentlicht 20.06.2025 15:15:25
- Zuletzt bearbeitet 23.04.2026 15:31:56
Missing Authorization vulnerability in App Cheap App Builder app-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects App Builder: from n/a through <= 5.5.6.
CVE-2024-9302
- EPSS 0.59%
- Veröffentlicht 25.10.2024 07:15:05
- Zuletzt bearbeitet 05.11.2024 17:39:17
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_p...
CVE-2024-7651
- EPSS 0.45%
- Veröffentlicht 21.08.2024 06:15:12
- Zuletzt bearbeitet 08.04.2026 19:22:20
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Injection via the ‘app-builder-search’ parameter in all versions up to, and including, 4.2.6 due to insufficient escaping on the user s...
CVE-2024-32565
- EPSS 0.31%
- Veröffentlicht 18.04.2024 10:15:10
- Zuletzt bearbeitet 28.04.2026 19:24:47
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Appcheap.Io App Builder allows Stored XSS.This issue affects App Builder: from n/a through 3.8.8.
CVE-2024-31282
- EPSS 0.33%
- Veröffentlicht 10.04.2024 16:15:13
- Zuletzt bearbeitet 28.04.2026 19:24:20
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7.