Description
The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.
Published: 2024-06-11
Score: 8.1 High
EPSS: 1.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-59656 The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.
History

Fri, 10 Apr 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Rahamsolutions
Rahamsolutions build App Online
CPEs cpe:2.3:a:rahamsolutions:build_app_online:*:*:*:*:*:wordpress:*:*
Vendors & Products Rahamsolutions
Rahamsolutions build App Online
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code. The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.
Title Build App Online <= 1.0.21 - Account Takeover via Weak Password Reset Mechanism Build App Online <= 1.0.22 - Account Takeover via Weak Password Reset Mechanism
References

Wed, 05 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Buildapp
Buildapp build App Online
CPEs cpe:2.3:a:buildapp.online:build_app_online:*:*:*:*:*:wordpress:*:* cpe:2.3:a:buildapp:build_app_online:*:*:*:*:*:wordpress:*:*
Vendors & Products Buildapp.online
Buildapp.online build App Online
Buildapp
Buildapp build App Online

Wed, 05 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Buildapp.online
Buildapp.online build App Online
Weaknesses CWE-640
CPEs cpe:2.3:a:buildapp.online:build_app_online:*:*:*:*:*:wordpress:*:*
Vendors & Products Buildapp.online
Buildapp.online build App Online

Subscriptions

Buildapp Build App Online
Rahamsolutions Build App Online
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:33:26.719Z

Reserved: 2024-05-28T14:43:04.373Z

Link: CVE-2023-7264

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.098Z

cve-icon NVD

Status : Modified

Published: 2024-06-11T04:15:11.987

Modified: 2026-04-08T19:19:07.370

Link: CVE-2023-7264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses