medium · CVSS v3 5.4 · EPSS 0.00221
CVE-2026-103421
The WPMobile.App plugin for WordPress is vulnerable to stored cross‑site scripting via the REQUEST_URI parameter. Attackers can inject scrip
Overview
The WPMobile.App plugin for WordPress is vulnerable to stored cross‑site scripting via the REQUEST_URI parameter. Attackers can inject scripts that execute in users’ browsers when they view a page. This flaw affects all versions up to and including 11.84.
Description
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app's content mode to be configured as 'webview' (i.e., the 'speed' option is not set to '1'), which is a supported and still-shipped mode, though no longer the default.
Impact
Confidentiality: injected scripts can steal session cookies or perform actions on behalf of users. Integrity: scripts can modify page content. Availability: not directly impacted. Defenders: site owners, administrators, and users of the plugin.
Remediation
Upgrade to version 11.85 or later. If an upgrade is not possible, disable the webview content mode or set the 'speed' option to '1'. Additionally, apply input sanitization for REQUEST_URI or use a WAF to block XSS payloads.
Risk context
The CVE has a medium severity score of 5.4 and a very low EPSS of 0.00221, indicating a low probability of exploitation in the wild. Nonetheless, the vulnerability can affect any site using the plugin in webview mode.
Affected products
- WordPress WPMobile.App
- WordPress
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 5.4
- CVSS v4
- —
- EPSS
- 0.00221