CVE-2026-94541: WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature, and use those URLs to take over the targeted accounts. This exploit chain requires the plugin's mail-to-push feature (wpmobileautomail=1) to be enabled, as that setting is what causes outbound WordPress password-reset emails — including the reset URL and key — to be mirrored into the push row queue where they become accessible to the attacker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the mail-to-push feature (wpmobile_auto_mail), which mirrors password-reset emails into the push row queue.
WPMobile.App – Android and iOS App Builder wpmobile_auto_mail = disabled
Event History
Frequently Asked Questions
Which deployments are exposed to this takeover chain?
Sites running WPMobile.App versions through 11.82 are exposed if the mail-to-push feature is enabled with wpmobile_auto_mail=1. That feature mirrors WordPress password-reset messages into the plugin's push queue.
What does an attacker need to exploit the issue?
The attacker does not need authentication, user interaction, or prior privileges. They need the mail-to-push feature to be enabled and can target password-reset URLs for arbitrary users, including administrators.
What can happen if exploitation succeeds?
An attacker can obtain a targeted user's password-reset URL and reset key from the push queue, then use the URL to take over that account. Administrator account takeover can provide full control of the WordPress site.
What mitigation is available if updating is not immediately possible?
Disable the plugin's mail-to-push feature by ensuring wpmobile_auto_mail is not enabled. This breaks the described exploit chain by preventing password-reset emails from being mirrored into the accessible push queue.