---
id: CVE-2025-11881
title: >-
  The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to
  unauthorized access of data due to a missing capability check on the
  'myappp_verify' function in all versions up to, and including, 4.5.0
summary: >-
  The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to
  unauthorized access of data due to a missing capability check on the
  'myappp_verify' function in all versions up to, and including, 4.5.0. This
  makes it possible…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-862
published: '2025-10-30'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11881'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/apppresser/tags/4.5.0/inc/AppPresser_WPAPI_Mods.php#L162
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/apppresser/tags/4.5.0/inc/AppPresser_WPAPI_Mods.php#L879
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3385855/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/62c3f54c-6bfb-4f11-9457-a09d28f83175?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00304
epssPercentile: 0.21265
ingestedAt: '2026-10-08T10:28:18.737Z'
---

## Overview

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'myappp_verify' function in all versions up to, and including, 4.5.0. This makes it possible for unauthenticated attackers to extract sensitive data including plugin and theme names and version numbers, which can be used to facilitate targeted attacks against outdated or vulnerable components.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
