CPE
An unauthenticated authorization bypass vulnerability in WPMobile.App (<= 11.82) allows attackers to exfiltrate password-reset URLs via the mail-to-push feature and perform account takeover.