CVE-2026-103694: Mobile builder <= 1.4.2 - Subscriber+ Privilege Escalation to Admin
Published Oct 11, 2026
·Updated
The Mobile builder WordPress plugin through 1.4.2 does not properly restrict which user meta keys a logged-in user can update through one of its REST routes, allowing any user with a self-registered account, such as a customer, to grant themselves the administrator role.
Affected Software
1 affected component
Mobile builder Mobile builder WordPress plugin<=1.4.2
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
Description