Impact
The WPMobile.App – Android and iOS App Builder plugin for WordPress contains a stored cross‑site scripting flaw in all versions up to 11.84. The vulnerability arises from insufficient input sanitization and output escaping of the URI path segment following /android_json/search/. An unauthenticated attacker can inject arbitrary JavaScript code that will execute whenever a user visits a page that includes the injected content. This flaw is classified under CWE‑79 and can be leveraged to steal data, deface content, or launch phishing attacks within the webview environment.
Affected Systems
The amauric WPMobile.App – Android and iOS App Builder plugin is vulnerable in all versions through 11.84. WordPress sites that use this plugin and have the content mode configured as "webview" (i.e., the "speed" option is not set to "1") are affected.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, and the EPSS score is not available, so exploitation likelihood cannot be determined from public data. The flaw is not listed in the CISA KEV catalog. Because the attack vector is unauthenticated and the injection is performed via a publicly accessible URL, the risk is moderate but tangible for sites that employ the vulnerable app mode.
OpenCVE Enrichment