App Builder – Create Native Android & iOS Apps On The Flight
App Builder – Create Native Android & iOS Apps On The Flight has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; 5 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 4 disclosures.
The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (14%). Other recurring categories include Cross-Site Scripting, Improper Privilege Management.
5 of the records (71%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2026.
7 independent researchers contributed these findings, one record each. App Builder – Create Native Android & iOS Apps On The Flight is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2026-2375App Builder – Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' Parameter
Read the full analysisVulnerability Records

App Builder – Create Native Android & iOS Apps On The Flight
Author
App Cheap
App builder works the same popular Page Builder in WordPress but it has a special UI/UX for your easy configuration/previews mobile app. App source code Features Set up user delete their account Brands for products Make color, image for attributes Set default login method On/Off captcha option WooCommerce Appointments WooCommerce Bookings Address Book Enable / Disable register Enable / Disable add to cart button Geo location Config Intenet connection notification Pickup address from map for checkout Chat GPT WC Cancel Order Wishlist Plugin Ajax search pro Plugin Cache app builder settings Multi-language app Share dynamic for product, post Cloud translate Support deeplink working with Permalink Hide Our of Stock Smart Coupon Add vertical payment method layout Cart Google fonts Add vertical shipping layout OneSignal Push Notifications Open App Link In Webview Sticky banner Dynamic form Reset password Identify App Orders Intercom Chat Upgrader Custom icons Captcha Integrations Woocommerce BuddyPress BbPress Product Add-Ons WooCommerce Brands WooCommerce Bookings Variation Swatches for WooCommerce Bookingwp Dokan WPML Polylang WCFM Marketplace Wcmp Photo Reviews for WooCommerce Customer Reviews for WooCommerce TeraWallet Geo My WP Advanced Custom Fields YITH WooCommerce Featured Video Product Video for WooCommerce Image Optimizer, Resizer and CDN – Sirv Checkout Field Manager (Checkout Manager) for WooCommerce by QuadLayers CURCY – Multi Currency for WooCommerce WooCommerce Multilingual & Multicurrency with WPML Smart Coupons Ajax Search Pro TI WooCommerce Wishlis WC Cancel Order B2BKing Pro Simple Local Avatars Translate Multilingual sites – TranslatePress YITH WooCommerce Badge Management YITH WooCommerce Order & Shipment Tracking WPC Linked Variation for WooCommerce WC Vendors Coupon Referral Program for WooCommerce Enable PHP HTTP Authorization Header Shared Hosts Most shared hosts have disabled the HTTP Authorization Header by default. To enable this option you’ll need to edit your .htaccess file by adding the following: RewriteEngine on RewriteCond %{HTTP:Authorization} ^(.*) RewriteRule ^(.*) - [E=HTTP_AUTHORIZATION:%1] WPEngine To enable this option you’ll need to edit your .htaccess file by adding the following (see https://github.com/Tmeister/wp-api-jwt-auth/issues/1): SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C