Sceawere

Vulnerability Detail

CVE-2026-103695UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Mobile Builder SQL Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
8h ago
Vendor
Unknown
Product
Mobile builder
Attack Type
CWE-89 SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Mobile builder WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-10-11T07:17:22.340Z",
  "pubdate": "2026-10-11T07:17:22.340Z",
  "executiveSummary": "The Mobile builder WordPress plugin, specifically versions up to and including 1.4.2, contains a critical SQL injection vulnerability. The flaw originates from the improper handling of user-supplied input before incorporating it into database queries.\nThis vulnerability allows unauthenticated remote attackers to execute arbitrary SQL commands against the underlying database. The impact of such an exploit is severe, as it grants unauthorized access to sensitive application data, including user credentials, configuration settings, and private content.\nThe primary risk implication is the potential for full database compromise, which could lead to administrative account takeover, data exfiltration, or the modification of site content. No authentication or specific user privileges are required to initiate an attack, as the vulnerable endpoint is exposed to any visitor.\nThe vulnerability highlights a critical failure in input validation and secure database query construction, which is common in legacy or poorly maintained plugins. Security teams should prioritize patching or restricting access to the affected plugin to mitigate the risk of automated exploitation.",
  "technicalDetails": "The root cause of this vulnerability is a failure to sanitize and escape input parameters before they are passed into a SQL query executed by the Mobile builder plugin. By failing to use prepared statements or robust database abstraction methods, the application implicitly trusts data received via HTTP requests.\nIn terms of attack flow, an attacker identifies an endpoint handled by the Mobile builder plugin that accepts a parameter from the user. Because this parameter is concatenated directly into a SQL string, the attacker can break out of the intended query structure by injecting SQL syntax characters such as single quotes ('), semicolons (;), or comments (--, #).\nAn unauthenticated attacker can craft a malicious HTTP GET or POST request containing a crafted payload. For example, by appending an 'OR 1=1' condition or utilizing UNION-based injection techniques, the attacker can manipulate the query results to return unauthorized data from other tables within the database schema.\nThe vulnerable component resides within the plugin’s data retrieval logic where the specific parameter is processed. Because the application lacks a layer of input validation (such as type casting or pattern matching) and output sanitization, the injected payload is executed with the privileges of the database user configured for the WordPress installation.\nThe exploit process typically involves: 1. Identification of the vulnerable parameter via trial-and-error using standard SQL injection testing strings. 2. Verification of injection feasibility through time-based or error-based indicators. 3. Exploitation to dump database contents, identify table structures, or perform administrative account enumeration.\nThe post-exploitation impact includes unauthorized data exposure, bypass of access control mechanisms, and the potential for persistent backdoors. If the database user possesses elevated privileges (e.g., FILE or administrative rights), the attacker may be able to read or write local files on the server or escalate the impact to Remote Code Execution (RCE) depending on the environment configuration."
}
CVE-2026-103695: Mobile Builder SQL Injection Vulnerability (HIGH Severity, CVSS: 8.6) | Sceawere