WPMobile.App ≤ 11.82 – Unauthenticated Administrator Account Takeover
CVE-2026-94541 is a critical unauthenticated administrator account takeover vulnerability in WPMobile.App ≤ 11.82 when mail-to-push is enabled. Update to 11.85 or newer.
WPMobile.App versions 11.82 and earlier contain a critical unauthenticated authorization bypass that can expose administrator password-reset URLs and lead to complete account takeover. The vulnerability is tracked as CVE-2026-94541 and carries a CVSS score of 9.8.
Wordfence reported 137 attacks targeting this vulnerability during the 24 hours preceding its latest record update. Exploitation requires the plugin’s mail-to-push feature to be enabled, but no WordPress account or user interaction is required.
Vulnerability summary
| Product | WPMobile.App – Android and iOS App Builder |
|---|---|
| Plugin slug | wpappninja |
| CVE | CVE-2026-94541 |
| Severity | Critical, CVSS 9.8 |
| Affected versions | All versions up to and including 11.82 |
| Fixed version | 11.85 |
| Authentication required | None |
| User interaction required | None |
| Required configuration | Mail-to-push enabled (wpmobile_auto_mail=1) |
| Potential impact | Administrator password-reset URL disclosure and account takeover |
How CVE-2026-94541 works
When mail-to-push is enabled, WPMobile.App mirrors outbound WordPress email into its push queue. That can include password-reset messages containing a reset key and URL. In affected versions, missing authorization around a request path associated with the wpapp_category[] parameter allows an unauthenticated attacker to access queued data that should remain private.
If an administrator’s reset message is present, the exposed URL can be used to set a new password for that account. The attacker can then authenticate as the administrator and take full control of the WordPress site.
The prerequisite reduces the number of affected configurations, but it does not reduce the impact on a vulnerable site. Wordfence’s observed attack traffic means administrators should update immediately rather than relying on the feature being obscure.
Immediate remediation
- Update WPMobile.App to version 11.85 or newer.
- If an immediate update is impossible, disable WPMobile.App or turn off mail-to-push until the patched version is installed.
- Purge page, object, plugin, CDN, and reverse-proxy caches after updating.
- Rotate administrator passwords and invalidate active sessions if mail-to-push was enabled on an affected version.
- Review administrator accounts, password-reset activity, WPMobile.App requests, and authentication logs for signs of unauthorized access.
Verify and update with WP-CLI
Check whether the plugin is installed and identify its version:
wp plugin get wpappninja --fields=name,status,version,update
Install the current security update:
wp plugin update wpappninja
Confirm that the resulting version is 11.85 or newer:
wp plugin get wpappninja --field=version
Temporary mitigation if patching is delayed
This is a temporary containment measure, not a substitute for updating. Disable the mail-to-push option and then purge caches:
wp option update wpmobile_auto_mail 0
wp cache flush
If the mobile-app integration is not business-critical, deactivate the vulnerable plugin until the update can be tested and deployed:
wp plugin deactivate wpappninja
Check for possible compromise
List administrator accounts and compare them with the expected owner list:
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
Review web-server and WAF logs for unusual requests containing the affected parameter name, repeated password-reset activity, or access to WPMobile.App endpoints:
grep -RInE "wpapp_category(%5B%5D|\[\])|lostpassword|resetpass|wpappninja" /var/log/nginx /var/log/apache2 2>/dev/null
Also check for recent changes that commonly follow administrator compromise:
wp plugin list
wp theme list
wp plugin list --status=must-use
wp cron event list
wp core verify-checksums
Unexpected administrator accounts, new plugins, modified themes, unfamiliar must-use plugins, or scheduled tasks require incident response. Preserve logs and file metadata before removing evidence.
Invalidate access after suspected takeover
Changing a password alone may not end every existing authenticated session. For each affected administrator ID, change the password through a trusted channel and destroy active sessions:
wp user session destroy ADMIN_ID --all
Rotate hosting, SFTP/SSH, database, API, payment, and WordPress application credentials that the compromised administrator could access. Regenerate WordPress security salts, scan the filesystem and database, and reinstall WordPress core, plugins, and themes from trusted packages where integrity cannot be established.
Sources
- Wordfence Intelligence: CVE-2026-94541 vulnerability record
- Official WPMobile.App plugin page and changelog
- CVE-2026-94541 record
WPDeeply did not discover this vulnerability. This advisory summarizes the public Wordfence disclosure and provides defensive remediation guidance.