CVE-2025-11881

AppPresser – Mobile App Framework <= 4.5.0 - Missing Authorization to Unauthenticated Limited Sensitive Information Exposure

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'myappp_verify' function in all versions up to, and including, 4.5.0. This makes it possible for unauthenticated attackers to extract sensitive data including plugin and theme names and version numbers, which can be used to facilitate targeted attacks against outdated or vulnerable components.


We have discovered 345 live websites that are affected by CVE-2025-11881.

Run a Free Instant Scan




Affected Software

Product  Apppresser
Category Wordpress Plugins
Vulnerable Domains345 live websites (86% of Apppresser install base)
Vulnerable Versions
  • from 0 through 4.5
Vulnerable Versions Count28 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Oct 30, 2025
  • Updated - Oct 30, 2025

Credits

  • D01EXPLOIT OFFICIAL (finder)

Website Distribution by Country

Number of websites using CVE-2025-11881
United States183 websites



Italy19 websites
GB18 websites
Germany18 websites
Canada11 websites
Iran11 websites
France7 websites
Russia6 websites
Netherlands5 websites
Denmark5 websites

Website Distribution by TLD

Number of websites using CVE-2025-11881
.com163 websites
.org43 websites
.net10 websites
.co.uk9 websites
.it9 websites
.ca8 websites
.de8 websites
.ru6 websites
.nl6 websites
.pl4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-11881

Top websites that are affected by CVE-2025-11881. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.com United States**,***
**************.com United States***,***
*************.com South Africa***,***
****.***.il Israel***,***
*******.gov United States***,***
******.com United States***,***
********.network United States***,***
******.org United States***,***
*********.ca Canada***,***
*************.is Iceland***,***
See full domain list

FAQ

CVE-2025-11881 is Missing Authorization in Apppresser
A total of 345 websites have been identified as vulnerable to CVE-2025-11881, based on global website indexing conducted by WebTechSurvey.
The Apppresser is affected by the CVE-2025-11881 vulnerability.
Apppresser versions up to and including 4.5 are vulnerable to CVE-2025-11881.