Sceawere
Vulnerability Detail
CVE-2026-94541UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WPMobile.App Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 13h ago
- Vendor
- amauric
- Product
- WPMobile.App – Android and iOS App Builder
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature, and use those URLs to take over the targeted accounts. This exploit chain requires the plugin's mail-to-push feature (wpmobile_auto_mail=1) to be enabled, as that setting is what causes outbound WordPress password-reset emails — including the reset URL and key — to be mirrored into the push row queue where they become accessible to the attacker.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-02T10:17:09.313Z",
"pubdate": "2026-10-02T10:17:09.313Z",
"executiveSummary": "The WPMobile.App – Android and iOS App Builder plugin for WordPress is susceptible to an authorization bypass vulnerability affecting all versions up to and including 11.82.\nThe vulnerability arises from an improper access control implementation, which allows unauthenticated remote attackers to exfiltrate sensitive data from the plugin's push notification queue.\nThe primary impact involves the unauthorized retrieval of WordPress password-reset URLs for arbitrary users, including site administrators. By intercepting these URLs, an attacker can facilitate full account takeover.\nExploitation is strictly contingent upon the 'mail-to-push' feature (wpmobile_auto_mail=1) being enabled within the plugin configuration. This feature mirrors outbound WordPress password-reset emails, containing the password reset key and URL, into a push row queue.\nBecause the plugin fails to verify the authorization status of the requester, the contents of this queue are accessible to unauthenticated entities. This flaw poses a critical risk to site integrity and administrative security, as it provides a trivial path to credential compromise and unauthorized account access.",
"technicalDetails": "The root cause of this vulnerability is a failure in the WPMobile.App plugin's authorization logic, which does not enforce strict access control checks on endpoints responsible for interacting with the push notification queue.\nWhen the mail-to-push functionality is active (configured via wpmobile_auto_mail=1), the plugin intercepts outbound WordPress password-reset emails to mirror them into a database queue for subsequent mobile push delivery. This mirror process includes the full body of the email, which contains the uniquely generated password reset URL and security token.\nThe vulnerability exists because the API or administrative interface responsible for displaying or fetching these push queue items lacks mandatory authentication and authorization checks. Consequently, an unauthenticated attacker can query the relevant endpoint to retrieve the contents of the queue.\nThe attack flow proceeds as follows: First, the attacker identifies a target account, such as an administrator. Second, the attacker triggers a password reset request through the standard WordPress functionality, causing an email containing a password-reset URL to be sent. Third, because the mail-to-push feature is enabled, the plugin automatically captures and inserts the content of this email—including the secret reset link—into the plugin's push row database table. Fourth, the attacker interacts with the vulnerable endpoint to exfiltrate the recently stored push notifications. Finally, the attacker utilizes the obtained reset URL to change the password of the victim's account, thereby achieving complete account takeover.\nThis vulnerability is categorized as a broken access control issue, specifically an Improper Authorization flaw. The lack of validation ensures that any request reaching the plugin's data retrieval function is processed without verifying if the user has appropriate privileges to access the queue data. Since the plugin mirrors raw email content into a public-facing queue mechanism, it creates an insecure exposure point for highly sensitive security tokens. The attack is executable via standard network requests, requiring no prior authentication or administrative access to the WordPress dashboard, provided the specific plugin feature is enabled. The post-exploitation impact is severe, granting attackers unauthorized administrative access and the ability to manipulate site content, settings, or user databases."
}