{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/wpmobile.app/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpmobile:wpmobile.app:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-94541"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=81C43653-71B6-534E-92D7-A63D7A83829B\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["WPMobile.App – Android and iOS App Builder (\u003c= 11.82)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WPMobile.App"],"content_html":"\u003cp\u003eThe WPMobile.App - Android and iOS App Builder plugin for WordPress is affected by an authorization bypass vulnerability identified as CVE-2026-94541. The vulnerability exists in all versions up to and including 11.82. It stems from improper authorization checks when handling internal plugin data. Specifically, when the plugin's 'mail-to-push' feature (wpmobile_auto_mail=1) is active, WordPress password-reset emails - which contain sensitive password-reset URLs and tokens - are incorrectly mirrored into a push notification queue. Because this queue lacks sufficient access controls, unauthenticated remote attackers can query the endpoint, extract the reset tokens for arbitrary accounts (including administrative accounts), and subsequently perform account takeover. This flaw represents a significant risk to WordPress sites utilizing this plugin for mobile app synchronization, as it grants attackers a direct path to privilege escalation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site utilizing the WPMobile.App plugin with the 'mail-to-push' feature enabled.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a password-reset request for an administrator account via the standard WordPress 'wp-login.php?action=lostpassword' endpoint.\u003c/li\u003e\n\u003cli\u003eWordPress generates a standard password-reset email containing the unique reset key and URL.\u003c/li\u003e\n\u003cli\u003eThe vulnerable plugin intercepts the email and copies the content, including the sensitive reset URL, into the plugin's push notification queue.\u003c/li\u003e\n\u003cli\u003eAttacker makes an unauthenticated HTTP request to the vulnerable plugin endpoint designed to serve the push queue.\u003c/li\u003e\n\u003cli\u003eThe plugin returns the contents of the queue, including the pending password-reset URL, due to a lack of authorization verification.\u003c/li\u003e\n\u003cli\u003eAttacker extracts the URL from the server response.\u003c/li\u003e\n\u003cli\u003eAttacker accesses the reset URL to set a new password for the administrator account, completing the account takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain full administrative access to compromised WordPress sites. This can lead to complete site compromise, data exfiltration, deployment of web shells, or redirection of site traffic to malicious domains. The scope is limited to WordPress installations running the affected plugin versions with the specific 'mail-to-push' configuration enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the WPMobile.App - Android and iOS App Builder plugin to version 11.83 or higher immediately to remediate CVE-2026-94541.\u003c/li\u003e\n\u003cli\u003eIf an immediate update is not possible, disable the 'mail-to-push' functionality within the plugin settings to prevent sensitive emails from being mirrored into the insecure queue.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts and review access logs for unusual password-reset activity originating from the plugin's API endpoints.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T12:34:31Z","date_published":"2026-10-02T10:23:15Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wpmobile-auth-bypass/","summary":"An unauthenticated authorization bypass vulnerability in WPMobile.App (\u003c= 11.82) allows attackers to exfiltrate password-reset URLs via the mail-to-push feature and perform account takeover.","title":"Authorization Bypass in WPMobile.App WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-wpmobile-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - WPMobile.App","version":"https://jsonfeed.org/version/1.1"}