---
id: CVE-2026-103421
title: >-
  The WPMobile.App – Android and iOS App Builder plugin for WordPress is
  vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment
  after /android_json/search/)' parameter in all versions up to, and including,
  11.84 due t…
summary: >-
  The WPMobile.App – Android and iOS App Builder plugin for WordPress is
  vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment
  after /android_json/search/)' parameter in all versions up to, and including,
  11.84 due t…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: amauric
product: WPMobile.App – Android and iOS App Builder
affected:
  - wpmobile.app_android_and_ios_app_builder <= 11.84
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T07:16:46.880'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103421'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/api/rewrite.php#L38
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/stats/boot.php#L91
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/stats/display.php#L361
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/stats/render.php#L74
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3721624'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/0dc77221-836b-45cd-a234-19dbf28ed0e7?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T07:40:49.049Z'
---

## Overview

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app's content mode to be configured as 'webview' (i.e., the 'speed' option is not set to '1'), which is a supported and still-shipped mode, though no longer the default.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
