Cyber & AI intelligence
Wasteland.
Briefs indexed2975
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-94541 2026-10-02

CVE-2026-94541: Unauthenticated Account Takeover in WPMobile.App WordPress Plugin

"A critical authorization bypass in the WPMobile.App – Android and iOS App Builder plugin for WordPress can let unauthenticated attackers read password-reset URLs and take over user accounts, including administrators…"

A critical authorization bypass in the WPMobile.App – Android and iOS App Builder plugin for WordPress can let unauthenticated attackers read password-reset URLs and take over user accounts, including administrators. This is only possible on sites where the plugin's mail-to-push feature is enabled.

What Is It

CVE-2026-94541 is a missing authorization flaw (CWE-862) in the WPMobile.App – Android and iOS App Builder plugin for WordPress. The plugin does not properly check whether a user is authorized to perform an action. Wordfence reported the issue, and NVD published it on 2026-10-02.

The attack depends on the plugin's mail-to-push feature (wpmobile_auto_mail=1). With that setting enabled, outgoing WordPress password-reset emails, including the reset URL and key, are copied into the plugin's push row queue. Because of the authorization bypass, an unauthenticated attacker can read reset URLs from that queue for any user and use them to take over the account.

Why It Matters

The CISA Known Exploited Vulnerabilities (KEV) Catalog has no entry for this CVE as of publication, so KEV does not currently confirm active exploitation. NVD lists the record's status as "Deferred."

What's Vulnerable

The Wordfence references point to code in inc/api/push.php, inc/api/read_enhanced.php, inc/common/deeplinking.php, and inc/functions/sdk2019.php.

Patch Status

The NVD record lists all versions through 11.82 as affected but does not name a fixed release. Because the CVE is not listed in the CISA KEV Catalog, there is no CISA KEV required action. Site owners should check the Wordfence advisory and the plugin's WordPress.org page for an updated version. Based on the exploit requirements in the NVD description, disabling the mail-to-push setting (wpmobile_auto_mail) removes the condition that exposes reset URLs.

Sources