A critical authorization bypass in the WPMobile.App – Android and iOS App Builder plugin for WordPress can let unauthenticated attackers read password-reset URLs and take over user accounts, including administrators. This is only possible on sites where the plugin's mail-to-push feature is enabled.
What Is It
CVE-2026-94541 is a missing authorization flaw (CWE-862) in the WPMobile.App – Android and iOS App Builder plugin for WordPress. The plugin does not properly check whether a user is authorized to perform an action. Wordfence reported the issue, and NVD published it on 2026-10-02.
The attack depends on the plugin's mail-to-push feature (wpmobile_auto_mail=1). With that setting enabled, outgoing WordPress password-reset emails, including the reset URL and key, are copied into the plugin's push row queue. Because of the authorization bypass, an unauthenticated attacker can read reset URLs from that queue for any user and use them to take over the account.
Why It Matters
- CVSS 3.1 score: 9.8 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - The attack works over the network with low complexity. It needs no privileges and no user interaction.
- Administrator accounts can be targeted, so a successful attack can give full control of the WordPress site.
The CISA Known Exploited Vulnerabilities (KEV) Catalog has no entry for this CVE as of publication, so KEV does not currently confirm active exploitation. NVD lists the record's status as "Deferred."
What's Vulnerable
- Vendor: amauric
- Product: WPMobile.App – Android and iOS App Builder (plugin slug:
wpappninja) - Affected versions: All versions up to and including 11.82
- Precondition: The mail-to-push feature (
wpmobile_auto_mail=1) must be enabled for the exploit chain to work.
The Wordfence references point to code in inc/api/push.php, inc/api/read_enhanced.php, inc/common/deeplinking.php, and inc/functions/sdk2019.php.
Patch Status
The NVD record lists all versions through 11.82 as affected but does not name a fixed release. Because the CVE is not listed in the CISA KEV Catalog, there is no CISA KEV required action. Site owners should check the Wordfence advisory and the plugin's WordPress.org page for an updated version. Based on the exploit requirements in the NVD description, disabling the mail-to-push setting (wpmobile_auto_mail) removes the condition that exposes reset URLs.