Vulnerabilities and security researches forwpappninja wpappninja
Direction: ascendingJun 07, 2024
WPMobile.App — Android and iOS Mobile Application # CVE-2023-22702
- CVE, Research URL
- Date
- Mar 23, 2023
- Research Description
- Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.13 versions.
- Affected versions
-
max 11.14.
- Status
-
vulnerable
WPMobile.App — Android and iOS Mobile Application # CVE-2023-28932
- CVE, Research URL
- Date
- May 10, 2023
- Research Description
- Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.20 versions.
- Affected versions
-
max 11.21.
- Status
-
vulnerable
WPMobile.App — Android and iOS Mobile Application # CVE-2023-26010
- CVE, Research URL
- Date
- May 04, 2023
- Research Description
- Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App plugin <= 11.18 versions.
- Affected versions
-
max 11.19.
- Status
-
vulnerable
Jun 10, 2024
WPMobile.App — Android and iOS Mobile Application # CVE-2024-35694
- CVE, Research URL
- Date
- Jun 08, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMobile.App allows Reflected XSS.This issue affects WPMobile.App: from n/a through 11.41.
- Affected versions
-
max 11.42.
- Status
-
vulnerable
Aug 29, 2024
WPMobile.App — Android and iOS Mobile Application # CVE-2024-43933
- CVE, Research URL
- Date
- Oct 31, 2024
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue affects WPMobile.App: from n/a through 11.48.
- Affected versions
-
max 11.49.
- Status
-
vulnerable
Oct 03, 2024
WPMobile.App — Android and iOS Mobile Application # CVE-2024-47349
- CVE, Research URL
- Date
- Oct 06, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMobile.App allows Reflected XSS.This issue affects WPMobile.App: from n/a through 11.50.
- Affected versions
-
max 11.51.
- Status
-
vulnerable
Dec 15, 2024
WPMobile.App — Android and iOS Mobile Application # CVE-2024-12420
- CVE, Research URL
- Date
- Dec 13, 2024
- Research Description
- The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 11.52. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
- Affected versions
-
max 11.53.
- Status
-
vulnerable
Feb 22, 2025
WPMobile.App — Android and iOS Mobile Application # CVE-2024-13888
- CVE, Research URL
- Date
- Feb 20, 2025
- Research Description
- The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
- Affected versions
-
max 11.57.
- Status
-
vulnerable
Nov 11, 2025
WPMobile.App — Android and iOS Mobile Application # CVE-2025-62074
- CVE, Research URL
- Date
- Nov 06, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.71.
- Affected versions
-
max 11.71.
- Status
-
vulnerable