Extension WordPress
Vulnérabilités AppPresser – Mobile App Framework
Cette page rassemble les failles publiées pour AppPresser – Mobile App Framework, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de AppPresser – Mobile App Framework
9 fiches
AppPresser – Mobile App Framework <= 4.5.0 – Missing Authorization to Unauthenticated Limited Sensitive Information Exposure
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'myappp_verify' function in all versions up to, and including, 4.5.0. This makes it possible…
*-4.5.0
4.5.1
29/10/2025
AppPresser – Mobile App Framework <= 4.4.10 – Unauthenticated Stored Cross-Site Scripting
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 4.4.10 due to insufficient input sanitization and output escaping. This makes it…
*-4.4.10
4.4.11
12/03/2025
AppPresser – Mobile App Framework <= 4.4.6 – Unauthenticated Privilege Escalation via Password Reset
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to the plugin not properly validating a user's password reset…
*-4.4.6
4.4.7
25/11/2024
AppPresser – Mobile App Framework <= 4.4.4 – Privilege Escalation and Account Takeover via Weak OTP
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() functions not having enough controls…
*-4.4.4
4.4.5
15/10/2024
AppPresser <= 4.3.2 – Improper Missing Encryption Exception Handling to Authentication Bypass
The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to log…
*-4.3.2
4.4.0
28/05/2024
AppPresser <= 4.3.0 – Missing Authorization
The AppPresser plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the toggle_logging_callback() function in versions up to, and including, 4.3.0. This makes it possible for unauthenticated attackers to enable…
*-4.3.0
4.3.1
22/04/2024
AppPresser <= 4.3.0 – Cross-Site Request Forgery via force_logging_off()
The AppPresser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0. This is due to missing or incorrect nonce validation on the force_logging_off() function. This makes it possible for unauthenticated attackers…
*-4.3.0
4.3.1
10/04/2024
AppPresser <= 4.3.0 – Cross-Site Request Forgery via toggle_logging_callback()
The AppPresser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0. This is due to missing or incorrect nonce validation on the toggle_logging_callback() function. This makes it possible for unauthenticated attackers…
*-4.3.0
4.3.1
05/04/2024
AppPresser <= 4.2.5 – Insecure Password Reset Mechanism
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password…
*-4.2.5
4.3.0
16/11/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.