CVE-2026-103694
Received Received - Intake

Mobile Builder WordPress Plugin Privilege Escalation to Admin

Vulnerability report for CVE-2026-103694, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Mobile builder WordPress plugin through 1.4.2 does not properly restrict which user meta keys a logged-in user can update through one of its REST routes, allowing any user with a self-registered account, such as a customer, to grant themselves the administrator role.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Mobile builder 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privilege escalation flaw in the Mobile builder WordPress plugin versions 1.4.2 and below. It allows users with self-registered accounts, such as subscribers, to grant themselves administrator privileges by exploiting a REST route that does not properly restrict user meta key updates.

Detection Guidance

Check if the Mobile builder WordPress plugin version 1.4.2 or below is installed. Look for unauthorized administrator role assignments in user meta data. Review REST API logs for suspicious meta key update requests.

Impact Analysis

An attacker with a self-registered account could escalate their privileges to administrator, gaining full control over the WordPress site. This could lead to unauthorized changes, data theft, or complete site takeover.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating compliance requirements for GDPR and HIPAA. It may result in unauthorized data exposure, fines, or legal consequences due to inadequate access controls.

Mitigation Strategies

Immediately update the Mobile builder plugin to the latest version if available. If no update exists, consider disabling the plugin until a patch is released. Restrict user registration to prevent self-registered accounts from gaining elevated privileges.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103694. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart