WordPress · Wpmobile.App · CVE-2026-103421
**Name of the Vulnerable Software and Affected Versions**
WPMobile.App – Android and iOS App Builder versions prior to 11.85
**Description**
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary web scripts into pages that execute when a user accesses them. This issue affects the `REQUEST URI` (specifically the path segment after `/android json/search/`) endpoint. Exploitation is possible when the app's content mode is configured as 'webview', which occurs when the `speed` option is not set to '1'.
**Recommendations**
Update to version 11.85 or later.
As a temporary mitigation, set the `speed` option to '1' to disable 'webview' content mode.