WPDeeply
Download free plugin
Plugin Security

WPMobile.App ≤ 11.82 – Unauthenticated Administrator Account Takeover

CVE-2026-94541 is a critical unauthenticated administrator account takeover vulnerability in WPMobile.App ≤ 11.82 when mail-to-push is enabled. Update to 11.85 or newer.

WPMobile.App administrator account takeover vulnerability CVE-2026-94541

WPMobile.App versions 11.82 and earlier contain a critical unauthenticated authorization bypass that can expose administrator password-reset URLs and lead to complete account takeover. The vulnerability is tracked as CVE-2026-94541 and carries a CVSS score of 9.8.

Wordfence reported 137 attacks targeting this vulnerability during the 24 hours preceding its latest record update. Exploitation requires the plugin’s mail-to-push feature to be enabled, but no WordPress account or user interaction is required.

Vulnerability summary

Product WPMobile.App – Android and iOS App Builder
Plugin slug wpappninja
CVE CVE-2026-94541
Severity Critical, CVSS 9.8
Affected versions All versions up to and including 11.82
Fixed version 11.85
Authentication required None
User interaction required None
Required configuration Mail-to-push enabled (wpmobile_auto_mail=1)
Potential impact Administrator password-reset URL disclosure and account takeover

How CVE-2026-94541 works

When mail-to-push is enabled, WPMobile.App mirrors outbound WordPress email into its push queue. That can include password-reset messages containing a reset key and URL. In affected versions, missing authorization around a request path associated with the wpapp_category[] parameter allows an unauthenticated attacker to access queued data that should remain private.

If an administrator’s reset message is present, the exposed URL can be used to set a new password for that account. The attacker can then authenticate as the administrator and take full control of the WordPress site.

The prerequisite reduces the number of affected configurations, but it does not reduce the impact on a vulnerable site. Wordfence’s observed attack traffic means administrators should update immediately rather than relying on the feature being obscure.

Immediate remediation

  1. Update WPMobile.App to version 11.85 or newer.
  2. If an immediate update is impossible, disable WPMobile.App or turn off mail-to-push until the patched version is installed.
  3. Purge page, object, plugin, CDN, and reverse-proxy caches after updating.
  4. Rotate administrator passwords and invalidate active sessions if mail-to-push was enabled on an affected version.
  5. Review administrator accounts, password-reset activity, WPMobile.App requests, and authentication logs for signs of unauthorized access.

Verify and update with WP-CLI

Check whether the plugin is installed and identify its version:

wp plugin get wpappninja --fields=name,status,version,update

Install the current security update:

wp plugin update wpappninja

Confirm that the resulting version is 11.85 or newer:

wp plugin get wpappninja --field=version

Temporary mitigation if patching is delayed

This is a temporary containment measure, not a substitute for updating. Disable the mail-to-push option and then purge caches:

wp option update wpmobile_auto_mail 0
wp cache flush

If the mobile-app integration is not business-critical, deactivate the vulnerable plugin until the update can be tested and deployed:

wp plugin deactivate wpappninja

Check for possible compromise

List administrator accounts and compare them with the expected owner list:

wp user list --role=administrator --fields=ID,user_login,user_email,user_registered

Review web-server and WAF logs for unusual requests containing the affected parameter name, repeated password-reset activity, or access to WPMobile.App endpoints:

grep -RInE "wpapp_category(%5B%5D|\[\])|lostpassword|resetpass|wpappninja" /var/log/nginx /var/log/apache2 2>/dev/null

Also check for recent changes that commonly follow administrator compromise:

wp plugin list
wp theme list
wp plugin list --status=must-use
wp cron event list
wp core verify-checksums

Unexpected administrator accounts, new plugins, modified themes, unfamiliar must-use plugins, or scheduled tasks require incident response. Preserve logs and file metadata before removing evidence.

Invalidate access after suspected takeover

Changing a password alone may not end every existing authenticated session. For each affected administrator ID, change the password through a trusted channel and destroy active sessions:

wp user session destroy ADMIN_ID --all

Rotate hosting, SFTP/SSH, database, API, payment, and WordPress application credentials that the compromised administrator could access. Regenerate WordPress security salts, scan the filesystem and database, and reinstall WordPress core, plugins, and themes from trusted packages where integrity cannot be established.

Sources

WPDeeply did not discover this vulnerability. This advisory summarizes the public Wordfence disclosure and provides defensive remediation guidance.

WPdeeply

WPDeeply is the site's editorial account for WordPress security advisories, plugin risk research, and remediation guides. Articles under this byline are checked against vendor changelogs, CVE records, vulnerability database entries, and the WPDeeply editorial policy before publication.