← Back to the live CVE advisory feed

CVE-2026-94541: WPMobile.App – Android and iOS App Builder

Severity
9.8 (CRITICAL)
Vendor
AMAURIC
Affected versions
0 through 11.82
Patch status
Unknown
Published
2026-10-02T10:17:09.313
Modified
2026-10-02T10:17:09.313

Why it matters

This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.

Recommended admin actions

  • Prioritize validation immediately due to critical CVSS severity.
  • Check whether the affected WordPress plugin or theme is installed.
  • Update, disable, or remove the affected component if present.
  • Treat internet-facing systems as higher priority.

Technical summary

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature, and use those URLs to take over the targeted accounts. This exploit chain requires the plugin's mail-to-push feature (wpmobile_auto_mail=1) to be enabled, as that setting is what causes outbound WordPress password-reset emails — including the reset URL and key — to be mirrored into the push row queue where they become accessible to the attacker.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 02, 2026 12:00 PM UTC
377 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-55393
Product identification pending
Reporter: MANDIANT-CVE
10
CRITICAL
VIEW RECORD
CVE-2026-79901
BoKS Manager boks-server
Reporter: DF4DEE71-DE3A-4139-9588-11B62FE6C0FF
9.9
CRITICAL
VIEW RECORD
CVE-2026-96658
Product identification pending
Reporter: SECALERT
9.9
CRITICAL
VIEW RECORD
CVE-2026-93698
cPanel
Reporter: SUPPORT
9.9
CRITICAL
VIEW RECORD
CVE-2026-103752
Authorizer PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-12627
Fortra's Core Privileged Access Manager (BoKS)
Reporter: DF4DEE71-DE3A-4139-9588-11B62FE6C0FF
9.8
CRITICAL
VIEW RECORD
CVE-2026-56154
Product identification pending
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-57941
Product identification pending
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-59797
Product identification pending
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-104286 EXPLOITED
FortiMail
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-14378
DevKit Pro
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-19660
Divi Membership
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-97637
JSON API Auth
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-94541
WPMobile.App – Android and iOS App Builder
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-56662
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-94620
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.4
CRITICAL
VIEW RECORD
CVE-2026-14984
Product identification pending
Reporter: MANDIANT-CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-55395
Product identification pending
Reporter: MANDIANT-CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-18397
Product identification pending
Reporter: PSIRT
9.4
CRITICAL
VIEW RECORD
CVE-2026-104480
Product identification pending PATCH
Reporter: 4AC701FE-44E9-4BCD-9585-DD6449257611
9.4
CRITICAL
VIEW RECORD
CVE-2026-86325
Product identification pending
Reporter: PSIRT
9.4
CRITICAL
VIEW RECORD
CVE-2026-62071
WordPress File Upload PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-13043
Endpoint Security
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
9.3
CRITICAL
VIEW RECORD
CVE-2026-103922
capacitor PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-71449
Product identification pending PATCH
Reporter: PRODUCTSECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-103764
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-102628
Product identification pending PATCH
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
9.2
CRITICAL
VIEW RECORD
CVE-2026-91135
Product identification pending PATCH
Reporter: SECURITY
9.2
CRITICAL
VIEW RECORD
CVE-2026-79898
BoKS Manager
Reporter: DF4DEE71-DE3A-4139-9588-11B62FE6C0FF
9.1
CRITICAL
VIEW RECORD
CVE-2026-96659
Product identification pending
Reporter: SECALERT
9.1
CRITICAL
VIEW RECORD
CVE-2026-55083
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-53953
GetSimpleCMS-CE
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-56660
GetSimpleCMS-CE PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-15896
Super Forms – Drag & Drop Form Builder
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-63569
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
9.1
CRITICAL
VIEW RECORD
CVE-2026-102667
Joyland.ai
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
9
CRITICAL
VIEW RECORD
CVE-2026-86345
Red Hat Directory Server 11
Reporter: SECALERT
9
CRITICAL
VIEW RECORD
CVE-2026-93029
cPanel
Reporter: SUPPORT
9
CRITICAL
VIEW RECORD
CVE-2026-93697
cPanel
Reporter: SUPPORT
9
CRITICAL
VIEW RECORD
CVE-2026-66246
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-103068
ByteCoreStack – MCP Connector for AI Tools PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-97284
Icegram PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-12405
Product identification pending
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-93546
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-104018
Product identification pending PATCH
Reporter: 0BF9931A-6EBF-4F48-BD14-39EE5E1D61F8
8.8
HIGH
VIEW RECORD
CVE-2026-103484
Product identification pending PATCH
Reporter: F86EF6DC-4D3A-42AD-8F28-E6D5547A5007
8.8
HIGH
VIEW RECORD
CVE-2026-70650
GetSimpleCMS-CE
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-104051
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-103765
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-15897
Super Forms – Drag & Drop Form Builder
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-80298
Product identification pending PATCH
Reporter: ILETISIM
8.8
HIGH
VIEW RECORD
CVE-2024-58388
Multiple Multifunction Printers
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-102369
Tapo C200 v5
Reporter: F23511DB-6C3E-4E32-A477-6AA17D310630
8.7
HIGH
VIEW RECORD
CVE-2026-104057
podgrab
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-55230
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-54049
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-71542
GetSimpleCMS-CE
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104020
Product identification pending PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
8.7
HIGH
VIEW RECORD
CVE-2026-103761
Mooncake
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-16000
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-63566
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-63568
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-103600
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-103603
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-103604
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-17507
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-63571
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-63574
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-94635
Product identification pending PATCH
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-85493
Product identification pending PATCH
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-85494
Product identification pending PATCH
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-91137
Product identification pending PATCH
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-93925
Product identification pending PATCH
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-93926
Product identification pending PATCH
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-94633
Product identification pending PATCH
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-94642
Product identification pending PATCH
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-95588
AcyMailing SMTP Newsletter PATCH
Reporter: AUDIT
8.6
HIGH
VIEW RECORD
CVE-2026-101888
Prime Mover PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-103766
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-86326
Product identification pending
Reporter: PSIRT
8.6
HIGH
VIEW RECORD
CVE-2026-102379
BuildKit – Product Builder for WooCommerce – Custom PC Builder PATCH
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-103338
Product identification pending
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-102294
TL-WR841N v14
Reporter: F23511DB-6C3E-4E32-A477-6AA17D310630
8.5
HIGH
VIEW RECORD
CVE-2026-55396
Product identification pending
Reporter: MANDIANT-CVE
8.5
HIGH
VIEW RECORD
CVE-2026-73975
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-102514
PeaZip
Reporter: 4DAA8CEA-433A-44BD-9456-53B127FC289A
8.4
HIGH
VIEW RECORD
CVE-2026-101322
Product identification pending PATCH
Reporter: EMO
8.3
HIGH
VIEW RECORD
CVE-2026-94250
Product identification pending PATCH
Reporter: SECURITY
8.2
HIGH
VIEW RECORD
CVE-2026-12540
Product identification pending
Reporter: SECALERT
8.2
HIGH
VIEW RECORD
CVE-2026-12541
Product identification pending
Reporter: SECALERT
8.2
HIGH
VIEW RECORD
CVE-2023-54404
Product identification pending
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-96780
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-104356
Product identification pending PATCH
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-103760
Mooncake
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-15999
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-16001
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-63567
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-103601
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-103602
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-18036
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.