Description
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app's content mode to be configured as 'webview' (i.e., the 'speed' option is not set to '1'), which is a supported and still-shipped mode, though no longer the default.
Published: 2026-10-03
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross Site Scripting
Action: Patch Now
AI Analysis

Impact

The WPMobile.App – Android and iOS App Builder plugin for WordPress contains a stored cross‑site scripting flaw in all versions up to 11.84. The vulnerability arises from insufficient input sanitization and output escaping of the URI path segment following /android_json/search/. An unauthenticated attacker can inject arbitrary JavaScript code that will execute whenever a user visits a page that includes the injected content. This flaw is classified under CWE‑79 and can be leveraged to steal data, deface content, or launch phishing attacks within the webview environment.

Affected Systems

The amauric WPMobile.App – Android and iOS App Builder plugin is vulnerable in all versions through 11.84. WordPress sites that use this plugin and have the content mode configured as "webview" (i.e., the "speed" option is not set to "1") are affected.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity, and the EPSS score is not available, so exploitation likelihood cannot be determined from public data. The flaw is not listed in the CISA KEV catalog. Because the attack vector is unauthenticated and the injection is performed via a publicly accessible URL, the risk is moderate but tangible for sites that employ the vulnerable app mode.

Generated by OpenCVE AI on October 3, 2026 at 08:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WPMobile.App plugin to version 11.85 or later.
  • If an upgrade cannot be performed immediately, configure the app to use the default "speed" option of 1 to switch away from the vulnerable webview mode.
  • Implement proper input sanitization and output encoding for any custom code that processes the REQUEST_URI path segment.

Generated by OpenCVE AI on October 3, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app's content mode to be configured as 'webview' (i.e., the 'speed' option is not set to '1'), which is a supported and still-shipped mode, though no longer the default.
Title WPMobile.App <= 11.84 - Unauthenticated Stored Cross-Site Scripting via '/android_json/search/<value>/0' Path Segment
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:43.024Z

Reserved: 2026-09-30T14:51:05.234Z

Link: CVE-2026-103421

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:59.013Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:46.880

Modified: 2026-10-03T16:16:33.030

Link: CVE-2026-103421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T09:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')