CVE-2026-7638
Last modified
CVE-2026-7638 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization validation in the `upload_avatar()` function, which accepts an attacker-controlled `user_id` parameter from the POST request body and uses it to update user meta without verifying that the authenticated requester owns or has permission to modify the target account. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization validation in the `upload_avatar()` function, which accepts an attacker-controlled `user_id` parameter from the POST request body and uses it to update user meta without verifying that the authenticated requester owns or has permission to modify the target account. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the profile avatar of any arbitrary user on the site, including administrators, by supplying a target `user_id` in the request body to the `/wp-json/app-builder/v1/upload-avatar` endpoint.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7638?
How severe is CVE-2026-7638?
How do I fix CVE-2026-7638?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7632A vulnerability was determined in code-projects Online Hospi…7.3
- CVE-2026-7633A vulnerability was identified in Totolink N300RH 6.1c.1353_…6.5
- CVE-2026-7634The SlimStat Analytics plugin for WordPress is vulnerable to…7.2
- CVE-2026-7635The coreActivity: Activity Logging for WordPress plugin for …8.1
- CVE-2026-7636The Slider by Soliloquy – Responsive Image Slider for WordPr…4.3
- CVE-2026-7637The Boost plugin for WordPress is vulnerable to PHP Object I…9.8
- CVE-2026-7639Software installed and run as a non-privileged user may cond…7.8
- CVE-2026-7640The WP Customer Area plugin for WordPress is vulnerable to S…6.4
- CVE-2026-7641The Import and export users and customers plugin for WordPre…8.8
- CVE-2026-7642A vulnerability was detected in pskill9 website-downloader u…6.3
- CVE-2026-7643A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.…4.3
- CVE-2026-7644A vulnerability has been found in ChatGPTNextWeb NextChat up…7.3
Are you affected by CVE-2026-7638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
