Executive brief
The WpMobi plugin for WordPress, which provides mobile-related functionality, contains a security flaw that allows attackers to trick a site administrator into unintentionally changing plugin settings. By convincing an administrator to click a malicious link, an attacker can execute unauthorized scripts in the administrator's browser. This could lead to unauthorized configuration changes or further attacks against the site's management interface.
Technical details
The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation in the handleSaveGeneralSettings function. An unauthenticated attacker can exploit this by tricking a logged-in administrator into clicking a specially crafted link or visiting a malicious website. This allows the attacker to modify the plugin's General Settings. Furthermore, because the 'app_name' attribute is reflected without proper escaping when validation fails, the attacker can inject arbitrary web scripts (XSS) that execute in the administrator's browser session. The vulnerability exists in all versions up to and including 0.0.3.
Affected products
- WpMobi WpMobi 0.0.3 and below
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory
References
- https://plugins.trac.wordpress.org/browser/wp-mobi/trunk/admin_panel/CWpMobiGeneralSettings.class.php
- https://plugins.trac.wordpress.org/browser/wp-mobi/trunk/admin_panel/views/general_settings.php
- https://plugins.trac.wordpress.org/browser/wp-mobi/trunk/core/CCore.class.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5fbd1c5c-d23a-4f89-9225-514552d6ea70?source=cve