Home

Description

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the `verify_role()` function in `AuthTrails.php` explicitly whitelisting the `wcfm_vendor` role alongside `subscriber` and `customer`, and assigning it directly via `wp_insert_user()` without integrating with WCFM Marketplace's vendor approval workflow. This makes it possible for unauthenticated attackers to register an account with the `wcfm_vendor` role by supplying the `role` parameter in the `/wp-json/app-builder/v1/register` REST API endpoint, bypassing the standard WCFM vendor approval process and immediately gaining vendor-level privileges (product management, order access, store management) on sites where WCFM Marketplace is active.

PUBLISHED Reserved 2026-02-11 | Published 2026-03-21 | Updated 2026-04-08 | Assigner Wordfence




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-269 Improper Privilege Management

Product status

Default status
unaffected

Any version
affected

Timeline

2026-03-20:Disclosed

Credits

Gibran Abdillah finder

References

www.wordfence.com/...-692a-4a84-ba9b-1904a42786c1?source=cve

plugins.trac.wordpress.org/...Di/Service/Auth/AuthTrails.php

plugins.trac.wordpress.org/.../Service/Auth/RegisterAuth.php

cve.org (CVE-2026-2375)

nvd.nist.gov (CVE-2026-2375)

Download JSON