Description
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app's content mode to be configured as 'webview' (i.e., the 'speed' option is not set to '1'), which is a supported and still-shipped mode, though no longer the default.
Published: 2026-10-03
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No solution or workaround provided in the CVE record.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Amauric
Amauric wpmobile.app
Wordpress-extensions
Wordpress-extensions wpmobile.app
Vendors & Products Amauric
Amauric wpmobile.app
Wordpress-extensions
Wordpress-extensions wpmobile.app

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app's content mode to be configured as 'webview' (i.e., the 'speed' option is not set to '1'), which is a supported and still-shipped mode, though no longer the default.
Title WPMobile.App <= 11.84 - Unauthenticated Stored Cross-Site Scripting via '/android_json/search/<value>/0' Path Segment
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Amauric Wpmobile.app
Wordpress-extensions Wpmobile.app
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:43.024Z

Reserved: 2026-09-30T14:51:05.234Z

Link: CVE-2026-103421

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:59.013Z

cve-icon NVD

Status : Deferred

Published: 2026-10-03T07:16:46.880

Modified: 2026-10-06T15:04:52.637

Link: CVE-2026-103421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T20:50:21Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')