WpMobi WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WpMobi plugin for WordPress, affecting all versions through 0.0.3. The issue arises from inadequate nonce validation in the handleSaveGeneralSettings function, allowing unauthenticated attackers to alter the plugin's General Settings. Exploitation involves injecting unescaped scripts into the administrator's browser via the app_name attribute. This is possible by tricking an admin into clicking a link, with the injected script executing even if the app_name value is invalid and not saved in the database, as the form reverts to the attacker-supplied value on validation failure.

Impact

Exploitation of this vulnerability could lead to Cross-Site Scripting (XSS) attacks, where injected scripts are executed in the context of the administrator's browser.

Added: Jun 9, 2026, 5:43 AM
Updated: Jun 9, 2026, 5:43 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
6.9
remediation
0.0
relevance
9.4
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.