
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2375 is a privilege escalation vulnerability in the App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress, affecting all versions up to and including 5.5.10. The flaw allows unauthenticated attackers to register an account with the wcfm_vendor role by supplying a role parameter to the /wp-json/app-builder/v1/register REST API endpoint, bypassing WCFM Marketplace's vendor approval workflow. It was published on March 21, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, Wordfence).
The root cause is classified as CWE-269 (Improper Privilege Management). The verify_role() function in AuthTrails.php explicitly whitelists the wcfm_vendor role alongside subscriber and customer, and passes it directly to wp_insert_user() without invoking WCFM Marketplace's vendor approval workflow. Because the REST API endpoint /wp-json/app-builder/v1/register accepts a user-supplied role parameter without adequate server-side validation or authorization checks, any unauthenticated HTTP request can specify wcfm_vendor as the desired role and receive it immediately upon account creation (Feedly).
Successful exploitation grants an unauthenticated attacker immediate vendor-level privileges on WordPress sites running both the App Builder plugin and WCFM Marketplace. This includes the ability to manage products, access orders, and administer their own store — capabilities normally reserved for approved vendors. While there is no direct availability impact, the integrity and confidentiality of marketplace data (customer orders, product listings, store configurations) are at risk, and a malicious vendor account could be leveraged for fraud, data harvesting, or further privilege escalation (Feedly, Wordfence).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable over the network. The EPSS score is approximately 0.044%, suggesting relatively low observed exploitation probability at this time. No CISA KEV catalog listing has been identified, and no public exploit code or active in-the-wild exploitation campaigns have been confirmed as of the available data. Notably, no patch was available at the time of initial disclosure (Feedly, Wordfence).
/wp-json/)./wp-json/app-builder/v1/register to verify the endpoint is accessible and the plugin is active./wp-json/app-builder/v1/register with a JSON body including standard registration fields (username, email, password) and the additional parameter "role": "wcfm_vendor".verify_role() function in AuthTrails.php accepts wcfm_vendor as a whitelisted role and passes it to wp_insert_user(), creating the account with vendor-level privileges immediately — bypassing any WCFM approval workflow./wp-json/app-builder/v1/register containing a role parameter set to wcfm_vendor (or other elevated roles) in the request body.wcfm_vendor accounts created without corresponding WCFM approval workflow entries.wp_users / wp_usermeta with the wcfm_vendor role that lack corresponding WCFM vendor approval records or onboarding metadata.At the time of initial disclosure, no patch was available for the App Builder plugin. Site administrators running WCFM Marketplace alongside App Builder (≤ 5.5.10) should consider the following interim mitigations: disable the /wp-json/app-builder/v1/register REST API endpoint via a WAF rule or server-level block if self-registration is not required; restrict REST API access to authenticated users where possible; and audit existing wcfm_vendor accounts for unauthorized registrations. Monitor the plugin's official WordPress repository and vendor communications for a patched release and apply it immediately upon availability (Feedly, Wordfence).
Wordfence included CVE-2026-2375 in its weekly WordPress vulnerability report for the week of March 16–22, 2026, flagging it as a notable privilege escalation issue affecting sites using both the App Builder plugin and WCFM Marketplace. The vulnerability was also indexed by VulDB and tracked via the CVE Project's official repository. No significant broader media coverage or notable researcher commentary beyond these standard tracking sources has been identified (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."