CVE-2026-94541 is a missing-authorization vulnerability in the WPMobile.App – Android and iOS App Builder plugin for WordPress through version 11.82. When the mail-to-push feature is enabled, outbound WordPress password-reset emails, including reset URLs and keys, are mirrored into a push queue. Insufficient authorization verification allows unauthenticated attackers to retrieve these reset credentials and use them to take over arbitrary WordPress accounts, including administrator accounts.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The supplied repository contains 22 files, including 12 Python files, vulnerability metadata, documentation, dependencies, a sample target list, and three defensive artifacts. Listed file sizes total 90,436 bytes; the actual archive size, original repository URL, and Git reference were not supplied. README.md, demonstrate_impact.py, and fullchain_test.py are truncated, limiting verification of the complete exploit implementation. The claimed CVE, severity, and fixed-version information originate from the repository and were not independently validated. The reported vulnerability is missing authorization in WPMobile.App push-category subscription handling. An unauthenticated client associates a device with a victim's email-address category. If mail-to-push is enabled, administrative emails—including password-reset URLs—are reportedly mirrored into that category. demonstrate_impact.py orchestrates version checking, username/email reconnaissance, device registration, category injection, reset triggering, token retrieval, and optional password replacement. Its visible main function invokes these phases, but the token-retrieval and takeover implementations are omitted by truncation. Username discovery does not reliably establish administrative privileges: user ID 1, the first REST user, and RSS author names are only candidates. scan.py is a standalone scanner backed by core/target.py for normalization/deduplication, core/engine.py for concurrent execution and reports, and core/probe.py for version and exposure checks. It supports target lists, proxy settings, custom user agents, timeouts, and JSON output. Its active checks are heuristic rather than proof of sensitive-data access: response markers such as 'wpapp_category' or 'wpappninja' can produce positive findings without verifying persisted subscriptions. The scanner sends wpapp_category rather than wpapp_category[], supplies an arbitrary cookie without registering a device, and its reproduce mode simply repeats the same exposure probe. Therefore 'REPRODUCTION COMPLETE' does not demonstrate the full account-takeover chain. No local-only target restriction is enforced. verify_diagnostics.py similarly prints acceptance and vulnerability conclusions without substantive verification, and it and the lab test use unreliable lexicographic version comparisons. fullchain_test.py is a hardcoded localhost lab harness with privileged database access. It saves the admin password hash, deletes selected subscription/push records, registers a test device, injects admin@example.com, triggers a reset, and attempts takeover before restoring the hash. Direct database extraction does not prove remote unauthenticated queue retrieval. Restoration is not protected by a visible try/finally block, so failures may leave modified credentials; deleted push records are not visibly restored. The repository is not principally a framework exploit. Its auxiliary Nuclei template only fingerprints a plugin readme and a version-shaped string, without enforcing the <= 11.82 boundary or testing authorization. Suricata signatures identify category updates and enhanced-read probes. ModSecurity rules attempt to block unsafe/email categories, but do not implement authorization and require validation against PHP array parameter handling. --generate-defenses only prints artifact locations; it does not generate or validate rules. publish_to_github.py is a publication utility, not an exploit stage; it temporarily stores a token in a Git remote and performs a force push. No attacker-controlled exfiltration server, reverse shell, or unrelated destructive payload is visible.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authorization bypass in WPMobile.App versions through 11.82 allows unauthenticated attackers to retrieve password-reset URLs and keys mirrored into the push queue and use them to take over accounts, including administrator accounts. Exploitation requires the mail-to-push feature to be enabled (wpmobile_auto_mail=1).
Critical unauthenticated authorization-bypass flaw in the WPMobile.App WordPress plugin that can expose password-reset URLs and enable takeover of arbitrary WordPress accounts, including administrator accounts, when mail-to-push is enabled.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.