CVE-2024-11024
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to the plugin not properly validating a user's password reset code prior to updating their password. This makes it possible for unauthenticated attackers, with knowledge of a user's email address, to reset the user's password and gain access to their account.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.70%
- CWE
- CWE-230
- Published
- 2024-11-26
- Last modified
- 2026-04-09
Affected products
- scottopolis AppPresser – Mobile App Framework
- scottopolis AppPresser – Mobile App Framework
Weakness type
Related vulnerabilities
- CVE-2026-25659 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
- CVE-2026-25658 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
- CVE-2026-20086 — A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP)...
- CVE-2026-1461 — Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values
- CVE-2025-23225 — IBM MQ denial of service
- CVE-2024-10508 — RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
- CVE-2024-9781 — Improper Handling of Missing Values in Wireshark
- CVE-2024-6237 — 389-ds-base: unauthenticated user can trigger a dos by sending a specific extended search request