CVE-2026-94541: WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter

Published Oct 2, 2026
·
Updated

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature, and use those URLs to take over the targeted accounts. This exploit chain requires the plugin's mail-to-push feature (wpmobileautomail=1) to be enabled, as that setting is what causes outbound WordPress password-reset emails — including the reset URL and key — to be mirrored into the push row queue where they become accessible to the attacker.

Affected Software

1 affected component
WPMobile.App WPMobile.App – Android and iOS App Builder plugin for WordPress<=11.82

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable the mail-to-push feature (wpmobile_auto_mail), which mirrors password-reset emails into the push row queue.

    WPMobile.App – Android and iOS App Builder wpmobile_auto_mail = disabled

Event History

Oct 2, 2026
CVE Published
via MITRE·09:25 AM
Data Sourced
via MITRE·09:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this takeover chain?

Sites running WPMobile.App versions through 11.82 are exposed if the mail-to-push feature is enabled with wpmobile_auto_mail=1. That feature mirrors WordPress password-reset messages into the plugin's push queue.

2

What does an attacker need to exploit the issue?

The attacker does not need authentication, user interaction, or prior privileges. They need the mail-to-push feature to be enabled and can target password-reset URLs for arbitrary users, including administrators.

3

What can happen if exploitation succeeds?

An attacker can obtain a targeted user's password-reset URL and reset key from the push queue, then use the URL to take over that account. Administrator account takeover can provide full control of the WordPress site.

4

What mitigation is available if updating is not immediately possible?

Disable the plugin's mail-to-push feature by ensuring wpmobile_auto_mail is not enabled. This breaks the described exploit chain by preventing password-reset emails from being mirrored into the accessible push queue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203