CRITICAL🇵🇱 Wersja polska

CVE-2024-11024

CVSS 9.8v3.1pub. 2024-11-26upd. 2025-06-05

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to the plugin not properly validating a user's password reset code prior to updating their password. This makes it possible for unauthenticated attackers, with knowledge of a user's email address, to reset the user's password and gain access to their account.

🤖 AI Analysis
How it works

The plugin does not properly verify the password reset code before changing it. An attacker, knowing only the victim's email address, can initiate a password reset procedure and set a new password without possessing a valid verification token. As a result, an unauthenticated attacker gains full access to the user account, which classifies the vulnerability as an Auth Bypass leading to privilege escalation (LPE) in case of account takeover with elevated privileges.

Impact

An attacker can take over any WordPress user account, including administrator accounts, gaining full control over the website — ability to modify content, install malicious plugins, steal data, and further compromise the infrastructure.

Mitigation & patch

The AppPresser plugin must be updated immediately to a version higher than 4.4.6. A patch is available in the WordPress repository at the address indicated in the references (changeset 3192531). It is also recommended to verify access logs for unauthorized password changes and force all users to re-authenticate.

Who is affected

AppPresser – Mobile App Framework for WordPress in all versions up to and including 4.4.6.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apppresser

    APP
    Apppresser
    < 4.4.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassLPE
CWE
References

Related vulnerabilities

CVE-2025-1561HIGH7.2same product

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...

CVE-2024-9305HIGH8.1same product

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account t...

CVE-2024-4611HIGH8.1same product

The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'de...

CVE-2023-4214HIGH8.1same product

The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and inclu...

CVE-2024-32776MEDIUM6.5same product

Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a thro...