search
amauric
Trends
- 1WordPress app builder plugin hit by stored XSS flawโผ๐จ EUVD-2026-91951 ๐ Score: 5.4/10 (CVSS v3.1) ๐ฆ Product: WPMobile.App โ Android and iOS App Builder ๐ข Vendor: amauric ๐
A medium-severity vulnerability, tracked as EUVD-2026-91951 with a CVSS score of 5.4, has been disclosed in the WPMobile.App โ Android and iOS App Builder WordPress plugin by vendor amauric. The flaw is a stored cross-site scripting issue reachable via the REQUEST_URI parameter, meaning attackers could inject malicious scripts that persist and run in visitors' browsers. Administrators running the plugin are advised to check for an updated version.