PT-2026-104537 · WordPress · Wpmobile.App
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WPMobile.App – Android and iOS App Builder versions prior to 11.85
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary web scripts into pages that execute when a user accesses them. This issue affects the
REQUEST URI (specifically the path segment after /android json/search/) endpoint. Exploitation is possible when the app's content mode is configured as 'webview', which occurs when the speed option is not set to '1'.Recommendations
Update to version 11.85 or later.
As a temporary mitigation, set the
speed option to '1' to disable 'webview' content mode.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpmobile.App