PT-2026-26834 · Appcheap · The App Builder – Create Native Android & Ios Apps On The Flight

Gibran Abdillah

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-2375

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the verify role() function in AuthTrails.php explicitly whitelisting the wcfm vendor role alongside subscriber and customer, and assigning it directly via wp insert user() without integrating with WCFM Marketplace's vendor approval workflow. This makes it possible for unauthenticated attackers to register an account with the wcfm vendor role by supplying the role parameter in the /wp-json/app-builder/v1/register REST API endpoint, bypassing the standard WCFM vendor approval process and immediately gaining vendor-level privileges (product management, order access, store management) on sites where WCFM Marketplace is active.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-2375

Affected Products

The App Builder – Create Native Android & Ios Apps On The Flight