WPMobile.App <= 11.77 - Missing Authorization
medium
The WPMobile.App plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 11.77. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 11.77
- Fixed in:
- 11.78
- Disclosed:
- Aug 13, 2026
CVE-2026-61984 on NVD →
WPMobile.App [wpappninja] <= 11.71 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.71.
- Affected:
- up to 11.71
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-62074 on NVD →
WPMobile.App <= 11.71 - Unauthenticated Stored Cross-Site Scripting
high
The WPMobile.App plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.71 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...
- CVSS:
- 7.2
- Affected:
- up to 11.71
- Fixed in:
- 11.72
- Disclosed:
- Oct 26, 2025
CVE-2025-62074 on NVD →
WPMobile.App [wpappninja] < 11.57
unknown
[en] The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites i...
- Affected:
- up to 11.57
- Fixed in:
- 11.57
- Disclosed:
- Feb 20, 2025
CVE-2024-13888 on NVD →
WPMobile.App <= 11.56 - Open Redirect via 'redirect' Parameter
high
The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if the...
- CVSS:
- 7.2
- Affected:
- up to 11.56
- Fixed in:
- 11.57
- Disclosed:
- Feb 19, 2025
CVE-2024-13888 on NVD →
WPMobile.App [wpappninja] < 11.53
unknown
[en] The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 11.52. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes...
- Affected:
- up to 11.53
- Fixed in:
- 11.53
- Disclosed:
- Dec 13, 2024
CVE-2024-12420 on NVD →
WPMobile.App — Android and iOS Mobile Application <= 11.52 - Unauthenticated Arbitrary Shortcode Execution
medium
The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 11.52. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it po...
- CVSS:
- 6.5
- Affected:
- up to 11.52
- Fixed in:
- 11.53
- Disclosed:
- Dec 12, 2024
CVE-2024-12420 on NVD →
WPMobile.App [wpappninja] < 11.49
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue affects WPMobile.App: from n/a through 11.48.
- Affected:
- up to 11.49
- Fixed in:
- 11.49
- Disclosed:
- Oct 31, 2024
CVE-2024-43933 on NVD →
WPMobile.App [wpappninja] < 11.51
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMobile.App allows Reflected XSS.This issue affects WPMobile.App: from n/a through 11.50.
- Affected:
- up to 11.51
- Fixed in:
- 11.51
- Disclosed:
- Oct 6, 2024
CVE-2024-47349 on NVD →
WPMobile.App <= 11.50 - Reflected Cross-Site Scripting
medium
The WPMobile.App plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 11.50 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...
- CVSS:
- 6.1
- Affected:
- up to 11.50
- Fixed in:
- 11.51
- Disclosed:
- Sep 30, 2024
CVE-2024-47349 on NVD →
WPMobile.App <= 11.48 - Reflected Cross-Site Scripting
medium
The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 11.48 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 11.48
- Fixed in:
- 11.49
- Disclosed:
- Aug 26, 2024
CVE-2024-43933 on NVD →
WPMobile.App [wpappninja] < 11.42
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMobile.App allows Reflected XSS.This issue affects WPMobile.App: from n/a through 11.41.
- Affected:
- up to 11.42
- Fixed in:
- 11.42
- Disclosed:
- Jun 8, 2024
CVE-2024-35694 on NVD →
WPMobile.App — Android and iOS Mobile Application <= 11.41 - Reflected Cross-Site Scripting
medium
The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 11.41 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 11.41
- Fixed in:
- 11.42
- Disclosed:
- Jun 6, 2024
CVE-2024-35694 on NVD →
WPMobile.App [wpappninja] < 11.21
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.20 versions.
- Affected:
- up to 11.21
- Fixed in:
- 11.21
- Disclosed:
- May 10, 2023
CVE-2023-28932 on NVD →
WPMobile.App [wpappninja] < 11.19
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App plugin <= 11.18 versions.
- Affected:
- up to 11.19
- Fixed in:
- 11.19
- Disclosed:
- May 4, 2023
CVE-2023-26010 on NVD →
WPMobile.App <= 11.20 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WPMobile.App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $_POST['wpappninja']['app']['name'] parameter in versions up to, and including, 11.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers ,with administrator-level access...
- CVSS:
- 4.4
- Affected:
- up to 11.20
- Fixed in:
- 11.21
- Disclosed:
- Mar 30, 2023
CVE-2023-28932 on NVD →
WPMobile.App [wpappninja] < 11.14
unknown
[en] Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.13 versions.
- Affected:
- up to 11.14
- Fixed in:
- 11.14
- Disclosed:
- Mar 23, 2023
CVE-2023-22702 on NVD →
WPMobile.App — Android and iOS Mobile Application <= 11.18 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 11.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level acces...
- CVSS:
- 4.4
- Affected:
- up to 11.18
- Fixed in:
- 11.19
- Disclosed:
- Feb 23, 2023
CVE-2023-26010 on NVD →
WPMobile.App — Android and iOS Mobile Application <= 11.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes
medium
The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 11.13 due to insufficient input sanitization and output escaping on shortcode attributes. This makes it possible for authenticated attacke...
- CVSS:
- 6.4
- Affected:
- up to 11.13
- Fixed in:
- 11.14
- Disclosed:
- Jan 20, 2023
CVE-2023-22702 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database