WPHizmet

Eklenti güvenlik geçmişi

WPMobile.App güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) WPMobile.App – Android and iOS App Builder eklentisi için 10 açık kaydı bulunuyor; en yenisi 3 Ekim 2026 tarihli. Bunların 4 tanesi kritik veya yüksek önemde, 9 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 11.86.

Toplam kayıt
10
Kritik veya yüksek
4
Oturumsuz istismar
9
Son kayıt
3 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-103421Orta · 5,43 Ekim 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 11.84 ve öncesi · Oturum açmadan istismar edilebilir

    The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app's content mode to be configured as 'webview' (i.e., the 'speed' option is not set to '1'), which is a supported and still-shipped mode, though no longer the default.

  • CVE-2026-94541Kritik · 9,82 Ekim 2026

    eksik yetki denetimi

    Etkilenen sürümler: 11.82 ve öncesi · Oturum açmadan istismar edilebilir

    The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature, and use those URLs to take over the targeted accounts. This exploit chain requires the plugin's mail-to-push feature (wpmobile_auto_mail=1) to be enabled, as that setting is what causes outbound WordPress password-reset emails — including the reset URL and key — to be mirrored into the push row queue where they become accessible to the attacker.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-96342Orta · 6,930 Eylül 2026

    eksik yetki denetimi

    Etkilenen sürümler: 11.83 ve öncesi · Oturum açmadan istismar edilebilir

    Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.

  • CVE-2026-61984Yüksek · 7,513 Ağustos 2026

    eksik yetki denetimi

    Etkilenen sürümler: 11.77 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.

  • CVE-2025-62074Yüksek · 7,16 Kasım 2025

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 11.71 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.71.

  • CVE-2024-13888Orta · 6,120 Şubat 2025

    açık yönlendirme

    Etkilenen sürümler: 11.56 ve öncesi · Oturum açmadan istismar edilebilir

    The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

  • CVE-2024-43933Orta · 4,331 Ekim 2024

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 11.48 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja allows Stored XSS.This issue affects WPMobile.App: from n/a through <= 11.48.

  • CVE-2024-47349Yüksek · 7,16 Ekim 2024

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 11.50 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.50.

  • CVE-2024-35694Orta · 6,18 Haziran 2024

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 11.41 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.41.

  • CVE-2023-26010Orta · 4,84 Mayıs 2023

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 11.18 ve öncesi

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App plugin <= 11.18 versions.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.