Cross-Site Scripting Risk in Blappsta Mobile App Plugin by Your News App
CVE-2025-50053
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 December 2025
What is CVE-2025-50053?
The Blappsta Mobile App Plugin is affected by a vulnerability that allows for Cross-Site Scripting (XSS) through improper input handling during web page generation. This issue enables attackers to inject malicious scripts into web pages viewed by users. Such vulnerabilities can lead to unauthorized actions on behalf of users and can compromise sensitive information. It is critical for users of the Blappsta Mobile App Plugin, particularly those using versions up to 0.8.8.8, to implement necessary security measures and update their software to mitigate this risk.
Affected Version(s)
Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App <= 0.8.8.8
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Xuan Chien | Patchstack Bug Bounty Program