CVE-2026-94541
Received Received - Intake

Authorization Bypass in WPMobile.App WordPress Plugin

Vulnerability report for CVE-2026-94541, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature, and use those URLs to take over the targeted accounts. This exploit chain requires the plugin's mail-to-push feature (wpmobile_auto_mail=1) to be enabled, as that setting is what causes outbound WordPress password-reset emails β€” including the reset URL and key β€” to be mirrored into the push row queue where they become accessible to the attacker.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpmobile app to 11.82 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WPMobile.App plugin for WordPress has an authorization bypass flaw in versions up to 11.82. It fails to verify user permissions for actions, allowing unauthenticated attackers to steal password-reset URLs for any user, including admins. This happens via the plugin's mail-to-push feature, which mirrors password-reset emails into a push queue accessible to attackers.

Detection Guidance

Check if the WPMobile.App plugin is installed and its version is up to 11.82. Inspect WordPress logs for unusual password-reset URL exfiltration or push queue entries. Look for unauthorized access attempts or admin account takeover signs.

Impact Analysis

Attackers can take over user accounts, including admin accounts, by exploiting the stolen password-reset URLs. This could lead to unauthorized access to sensitive data, website control, or further attacks. The exploit requires the mail-to-push feature to be enabled.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access control. Organizations using this plugin may face compliance breaches, legal penalties, and reputational damage.

Mitigation Strategies

Update the WPMobile.App plugin to the latest version beyond 11.82. Disable the mail-to-push feature (wpmobile_auto_mail=1) if enabled. Review and revoke any suspicious password-reset URLs or admin account changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94541. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart