CVE-2026-2375: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2375 is a privilege escalation vulnerability in the App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress, affecting all versions up to and including 5.5.10. The flaw allows unauthenticated attackers to register an account with the wcfm_vendor role by supplying a role parameter to the /wp-json/app-builder/v1/register REST API endpoint, bypassing WCFM Marketplace's vendor approval workflow. It was published on March 21, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, Wordfence).

Technical details

The root cause is classified as CWE-269 (Improper Privilege Management). The verify_role() function in AuthTrails.php explicitly whitelists the wcfm_vendor role alongside subscriber and customer, and passes it directly to wp_insert_user() without invoking WCFM Marketplace's vendor approval workflow. Because the REST API endpoint /wp-json/app-builder/v1/register accepts a user-supplied role parameter without adequate server-side validation or authorization checks, any unauthenticated HTTP request can specify wcfm_vendor as the desired role and receive it immediately upon account creation (Feedly).

Impact

Successful exploitation grants an unauthenticated attacker immediate vendor-level privileges on WordPress sites running both the App Builder plugin and WCFM Marketplace. This includes the ability to manage products, access orders, and administer their own store — capabilities normally reserved for approved vendors. While there is no direct availability impact, the integrity and confidentiality of marketplace data (customer orders, product listings, store configurations) are at risk, and a malicious vendor account could be leveraged for fraud, data harvesting, or further privilege escalation (Feedly, Wordfence).

Exploitability

The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable over the network. The EPSS score is approximately 0.044%, suggesting relatively low observed exploitation probability at this time. No CISA KEV catalog listing has been identified, and no public exploit code or active in-the-wild exploitation campaigns have been confirmed as of the available data. Notably, no patch was available at the time of initial disclosure (Feedly, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running both the App Builder plugin (≤ 5.5.10) and WCFM Marketplace using tools like WPScan, Shodan, or by probing the REST API discovery endpoint (/wp-json/).
  2. Confirm endpoint availability: Send a GET request to /wp-json/app-builder/v1/register to verify the endpoint is accessible and the plugin is active.
  3. Craft malicious registration request: Send a POST request to /wp-json/app-builder/v1/register with a JSON body including standard registration fields (username, email, password) and the additional parameter "role": "wcfm_vendor".
  4. Account creation: The verify_role() function in AuthTrails.php accepts wcfm_vendor as a whitelisted role and passes it to wp_insert_user(), creating the account with vendor-level privileges immediately — bypassing any WCFM approval workflow.
  5. Exploit vendor access: Log in with the newly created account and access vendor-level functionality: create/manage product listings, view and manipulate orders, and manage store settings on the marketplace (Feedly).

Indicators of compromise

  • Network: Unexpected POST requests to /wp-json/app-builder/v1/register containing a role parameter set to wcfm_vendor (or other elevated roles) in the request body.
  • Logs: WordPress access logs showing REST API registration calls from unknown or suspicious IP addresses; authentication logs showing new wcfm_vendor accounts created without corresponding WCFM approval workflow entries.
  • WordPress Database: Presence of newly created user accounts in wp_users / wp_usermeta with the wcfm_vendor role that lack corresponding WCFM vendor approval records or onboarding metadata.
  • Behavior: Unexpected vendor store activity (new product listings, order access) from accounts with no prior approval history or business context (Feedly).

Mitigation and workarounds

At the time of initial disclosure, no patch was available for the App Builder plugin. Site administrators running WCFM Marketplace alongside App Builder (≤ 5.5.10) should consider the following interim mitigations: disable the /wp-json/app-builder/v1/register REST API endpoint via a WAF rule or server-level block if self-registration is not required; restrict REST API access to authenticated users where possible; and audit existing wcfm_vendor accounts for unauthorized registrations. Monitor the plugin's official WordPress repository and vendor communications for a patched release and apply it immediately upon availability (Feedly, Wordfence).

Community reactions

Wordfence included CVE-2026-2375 in its weekly WordPress vulnerability report for the week of March 16–22, 2026, flagging it as a notable privilege escalation issue affecting sites using both the App Builder plugin and WCFM Marketplace. The vulnerability was also indexed by VulDB and tracked via the CVE Project's official repository. No significant broader media coverage or notable researcher commentary beyond these standard tracking sources has been identified (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management