Authorization Bypass in WPMobile.App Plugin for WordPress
CVE-2026-94541
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-94541?
The WPMobile.App plugin for WordPress is susceptible to an authorization bypass vulnerability present in all versions up to 11.82. This security gap occurs because the plugin fails to adequately confirm whether a user is authorized to execute specific actions. As a result, unauthorized attackers may gain access to sensitive password-reset URLs of any user, including administrators. These URLs are inadvertently exposed in the push queue due to the plugin's mail-to-push feature when it's enabled. This situation poses a significant risk, as attackers can exploit these URLs to commandeer the affected accounts.
Affected Version(s)
WPMobile.App β Android and iOS App Builder 0 <= 11.82