Sceawere

Vulnerability Detail

CVE-2026-103421UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in WPMobile.App

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
amauric
Product
WPMobile.App – Android and iOS App Builder
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app's content mode to be configured as 'webview' (i.e., the 'speed' option is not set to '1'), which is a supported and still-shipped mode, though no longer the default.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-03T07:16:46.880Z",
  "pubdate": "2026-10-03T07:16:46.880Z",
  "executiveSummary": "The WPMobile.App – Android and iOS App Builder plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 11.84.\nThe vulnerability arises from improper sanitization and output escaping of the REQUEST_URI parameter within the /android_json/search/ endpoint.\nSuccessful exploitation allows unauthenticated attackers to inject and execute arbitrary JavaScript within the context of a victim's session.\nThe impact is significant, potentially leading to unauthorized actions, session hijacking, or sensitive data theft if an administrative or authenticated user views the injected page.\nExploitation is contingent upon the WordPress installation being configured to 'webview' mode (where the 'speed' option is not set to '1').\nGiven that this configuration remains a supported and native feature of the plugin, the risk to organizations currently utilizing this mode is high.",
  "technicalDetails": "The vulnerability is located in the request processing logic of the WPMobile.App plugin, specifically concerning the handling of the REQUEST_URI path segment following /android_json/search/.\nThe root cause is a failure to adequately sanitize user-supplied input before reflecting it back into the Document Object Model (DOM) of the rendered pages.\nThe vulnerable component processes the URI path to facilitate search queries; however, it fails to encode special characters, allowing for the injection of malicious script tags.\nAttackers can leverage this by crafting a malicious URI request containing an XSS payload. When a user—such as an administrator or authenticated user—navigates to the crafted URL, the injected script executes within the victim's browser context.\nBecause the payload is 'stored' or processed as part of the search query path, the attack flow involves the attacker sending an HTTP request to the target site containing the malicious path segment. The plugin subsequently embeds this raw input into the server's response.\nExploitation is strictly conditioned on the plugin being configured in 'webview' mode. In this mode, the plugin's architectural design facilitates the rendering of this unescaped content. Since this mode is still supported and shipped within the plugin's current codebase, the attack surface remains viable.\nThe attack does not require prior authentication, meaning it can be initiated by any remote attacker with network access to the WordPress instance.\nPost-exploitation, an attacker can manipulate the DOM, redirect users, capture authentication cookies, or perform unauthorized administrative actions on behalf of the victim through the hijacked session.\nThe lack of output escaping at the point of reflection in the plugin's response handling is the primary vector for this vulnerability, bypassing basic browser-level XSS protections in many instances where the server-side response explicitly includes the injected script elements."
}
CVE-2026-103421: Stored XSS in WPMobile.App (MEDIUM Severity, CVSS: 5.4) | Sceawere