Impact
The Mobile Builder plugin for WordPress includes an authentication bypass that allows attackers to gain privileged access without valid credentials by exploiting an alternate path. The flaw, identified as CWE-288, carries a CVSS score of 9.8, indicating a critical threat to the confidentiality, integrity, and availability of affected sites.
Affected Systems
All installations of the Mobile Builder WordPress plugin through version 1.4.2 are vulnerable. This includes all releases from the earliest available versions up to and including 1.4.2.
Risk and Exploitability
The EPSS score is less than 1%, indicating very low exploitation probability currently, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can exploit the flaw via a web request to an alternate path, providing full administrative control. The high CVSS score highlights the urgency for immediate remediation.
OpenCVE Enrichment