CVE-2026-103695: Mobile Builder <= 1.4.2 - Unauthenticated SQLi via 'vendor_id' Parameter
Published Oct 11, 2026
·Updated
The Mobile builder WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
Affected Software
1 affected component
Mobile Builder WordPress plugin<=1.4.2
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
Description