External risk intelligence

WPMobileApp Builder Plugin Authorization Bypass Allows Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-94541

The vulnerability exists in a WordPress plugin. WordPress sites are frequently deployed as public-facing web applications accessible via the internet. While the specific exploit requires a particular plugin feature to be enabled, the underlying product is designed for public web exposure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in a WordPress plugin allows unauthenticated attackers to bypass authorization. If a specific feature is enabled, attackers could exploit this to exfiltrate password reset URLs and take over user accounts, including those of administrators.

  • Unauthenticated access to reset links.
  • Account takeover risk for any user.
  • Confirm if the feature is enabled.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can compromise user accounts by exploiting an authorization bypass in the WPMobile.App WordPress plugin. This is possible when the plugin's mail-to-push feature is enabled, which causes password-reset URLs to be exposed in a push queue. An attacker can then access these URLs and use them to take over targeted accounts.

  • No prior authentication needed.
  • Exploits mail-to-push feature for URLs.
  • Allows account takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to obtain password-reset URLs for any user, including administrators, when the mail-to-push feature is enabled. These URLs could then be used to take over targeted accounts.

  • User and administrator account credentials.
  • Through an authorization bypass flaw.
  • Account takeover and unauthorized access.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WordPress plugin's authorization bypass vulnerability requires administrators to identify instances where the "mail-to-push" feature is enabled to prevent unauthenticated attackers from exfiltrating password-reset URLs. Website owners, application administrators, and potentially infrastructure teams should collaborate to locate affected sites, confirm the enabled feature, and plan for remediation, prioritizing critical or publicly exposed systems.

  • WordPress site owners and admins.
  • Verify "mail-to-push" feature is enabled.
  • Plan remediation for enabled features.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WPMobile.App plugin for WordPress?

WPMobile.App is a plugin designed to help website owners convert their existing WordPress content into native mobile applications for Android and iOS. It functions as an app builder, bridging the gap between web platforms and mobile storefronts by managing content synchronization and push notification delivery.

What does CWE-862 mean for CVE-2026-94541?

CWE-862 is the classification for Missing Authorization. In the context of this CVE, it means the plugin fails to verify if a user has permission to access specific data. Because this check is missing, the software allows unauthorized users to view sensitive information that should be restricted to administrators or the account owners themselves.

How does an attacker trigger this vulnerability?

An attacker triggers this by interacting with the plugin's API to access the push queue. This is only possible if the site has the 'mail-to-push' feature enabled. If this feature is turned off, the password-reset links are not mirrored into the push queue, meaning the specific pathway required to steal these URLs does not exist.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal indicates a 'Likely' risk level because this plugin is designed for public-facing WordPress sites. Since these applications are intentionally accessible via the internet to serve mobile users, they are reachable by unauthorized parties who might attempt to exploit this authorization flaw.

What should I do if I use this plugin?

Your first step is to verify if the 'mail-to-push' feature is currently active in your plugin settings. If it is enabled, you should immediately evaluate the necessity of this feature versus the risk of account takeover. If the feature is not strictly required, disabling it is the primary way to remove the current attack vector.

References