Extension WordPress
Vulnérabilités Build App Online
Cette page rassemble les failles publiées pour Build App Online, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Build App Online
9 fiches
Build App Online <= 1.0.23 – Missing Authorization to Arbitrary Post Author Modification via 'build-app-online-update-vendor-product' AJAX Action
The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. This is due to the plugin registering the 'build-app-online-update-vendor-product' AJAX action via wp_ajax_nopriv_ without proper authentication checks, capability…
*-1.0.23
Non indiqué
20/03/2026
Build App Online <= 1.0.23 – Cross-Site Request Forgery
The Build App Online plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.23. This is due to missing or incorrect nonce validation on a function. This makes it possible for…
*-1.0.23
Non indiqué
14/08/2025
Build App Online <= 1.0.23 – Unauthenticated Local File Inclusion
The Build App Online plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.23. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the…
*-1.0.23
Non indiqué
09/04/2025
Build App Online <= 1.0.23 – Unauthenticated Local File Inclusion
The Build App Online plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.23. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing…
*-1.0.23
Non indiqué
06/01/2025
Build App Online <= 1.0.22 – Cross-Site Request Forgery
The Build App Online plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.22. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated…
*-1.0.22
Non indiqué
28/11/2024
Build App Online <= 1.0.22 – Account Takeover via Weak Password Reset Mechanism
The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password…
*-1.0.22
1.0.23
27/12/2023
Build App Online <= 1.0.20 – Missing Authorization Authenticated(Subscriber+) Arbitrary Options Update
The Build App Online plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_user_meta' and 'update_user_meta_value' functions in all versions up to, and including, 1.0.20. This makes it possible…
*-1.0.20
1.0.21
27/12/2023
Build App Online <= 1.0.21 – Authentication Bypass via Header
The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.21. This is due to missing authentication checking in the 'set_user_cart' function with the 'user_id' header value. This makes it…
*-1.0.21
1.0.22
27/12/2023
Build App Online <= 1.0.18 – Unauthenticated SQL Injection
The Build App Online plugin for WordPress is vulnerable to SQL Injection via an AJAX action available to unprivileged users in versions up to, and including, 1.0.18 due to insufficient escaping on the user supplied parameter and lack…
*-1.0.18
1.0.19
06/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.