<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WPMobile.App - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/wpmobile.app/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 10:23:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/wpmobile.app/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in WPMobile.App WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-wpmobile-auth-bypass/</link><pubDate>Fri, 02 Oct 2026 10:23:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wpmobile-auth-bypass/</guid><description>An unauthenticated authorization bypass vulnerability in WPMobile.App (&lt;= 11.82) allows attackers to exfiltrate password-reset URLs via the mail-to-push feature and perform account takeover.</description><content:encoded><![CDATA[<p>The WPMobile.App - Android and iOS App Builder plugin for WordPress is affected by an authorization bypass vulnerability identified as CVE-2026-94541. The vulnerability exists in all versions up to and including 11.82. It stems from improper authorization checks when handling internal plugin data. Specifically, when the plugin's 'mail-to-push' feature (wpmobile_auto_mail=1) is active, WordPress password-reset emails - which contain sensitive password-reset URLs and tokens - are incorrectly mirrored into a push notification queue. Because this queue lacks sufficient access controls, unauthenticated remote attackers can query the endpoint, extract the reset tokens for arbitrary accounts (including administrative accounts), and subsequently perform account takeover. This flaw represents a significant risk to WordPress sites utilizing this plugin for mobile app synchronization, as it grants attackers a direct path to privilege escalation.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a WordPress site utilizing the WPMobile.App plugin with the 'mail-to-push' feature enabled.</li>
<li>Attacker triggers a password-reset request for an administrator account via the standard WordPress 'wp-login.php?action=lostpassword' endpoint.</li>
<li>WordPress generates a standard password-reset email containing the unique reset key and URL.</li>
<li>The vulnerable plugin intercepts the email and copies the content, including the sensitive reset URL, into the plugin's push notification queue.</li>
<li>Attacker makes an unauthenticated HTTP request to the vulnerable plugin endpoint designed to serve the push queue.</li>
<li>The plugin returns the contents of the queue, including the pending password-reset URL, due to a lack of authorization verification.</li>
<li>Attacker extracts the URL from the server response.</li>
<li>Attacker accesses the reset URL to set a new password for the administrator account, completing the account takeover.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain full administrative access to compromised WordPress sites. This can lead to complete site compromise, data exfiltration, deployment of web shells, or redirection of site traffic to malicious domains. The scope is limited to WordPress installations running the affected plugin versions with the specific 'mail-to-push' configuration enabled.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the WPMobile.App - Android and iOS App Builder plugin to version 11.83 or higher immediately to remediate CVE-2026-94541.</li>
<li>If an immediate update is not possible, disable the 'mail-to-push' functionality within the plugin settings to prevent sensitive emails from being mirrored into the insecure queue.</li>
<li>Audit WordPress user accounts and review access logs for unusual password-reset activity originating from the plugin's API endpoints.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>