Executive brief
The Blappsta Mobile App Plugin for WordPress allows website administrators to offer native mobile apps for content delivery. This plugin contains a reflected cross-site scripting (XSS) vulnerability that could allow an attacker to inject malicious scripts into pages viewed by website visitors, potentially stealing their data or hijacking their accounts. Exploitation requires tricking a user into clicking a malicious link or visiting a crafted page.
Technical details
This is a reflected XSS vulnerability (CWE-79) in the Blappsta Mobile App Plugin for WordPress affecting versions through 0.8.8.8. The vulnerability stems from improper neutralization of user-supplied input during web page generation, allowing attackers to inject arbitrary JavaScript into the application. The attack is network-accessible and requires user interaction (a victim must click a malicious link or visit a crafted page), but does not require authentication. An attacker can execute arbitrary scripts in the context of the victim's browser session, potentially stealing session cookies, credentials, or other sensitive data. As of the advisory date, no official patch is available; Patchstack has issued a mitigation rule.
Affected products
- nebelhorn Blappsta Mobile App Plugin through 0.8.8.8
Timeline
- 2025-06-23: disclosed
- 2025-07-23: advisory
- 2025-12-31: other: Published to NVD