CRITICAL
9.8 CVE-2026-94541 Published 2 Oct 2026
WordPress WPMobile.App Plugin Authorization Bypass Vulnerability
Worried this affects your website?
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to an authorization bypass in all versions up to, and including, 11.82. The plugin does not properly verify that a user is authorized to perform an action.
This makes it possible for unauthenticated attackers to:
- Exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature.
- Use those URLs to take over the targeted accounts.
The exploit chain requires the plugin's mail-to-push feature (wpmobile_auto_mail=1) to be enabled, as that setting causes outbound WordPress password-reset emails — including the reset URL and key — to be mirrored into the push row queue where they become accessible to the attacker.
Reference: CVE-2026-94541 on NVD
← Back to Security News