Junglewise Threat Intelligence

CVE-2026-8909: WpMobi WordPress plugin CSRF and XSS in handleSaveGeneralSettings

CVE-2026-8909 · Severity: medium · CVSS 4.3 · Published 2026-06-09

Executive brief

The WpMobi plugin for WordPress, which provides mobile-related functionality, contains a security flaw that allows attackers to trick a site administrator into unintentionally changing plugin settings. By convincing an administrator to click a malicious link, an attacker can execute unauthorized scripts in the administrator's browser. This could lead to unauthorized configuration changes or further attacks against the site's management interface.

Technical details

The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation in the handleSaveGeneralSettings function. An unauthenticated attacker can exploit this by tricking a logged-in administrator into clicking a specially crafted link or visiting a malicious website. This allows the attacker to modify the plugin's General Settings. Furthermore, because the 'app_name' attribute is reflected without proper escaping when validation fails, the attacker can inject arbitrary web scripts (XSS) that execute in the administrator's browser session. The vulnerability exists in all versions up to and including 0.0.3.

Affected products

  • WpMobi WpMobi 0.0.3 and below

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References