Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-94541

WPMobile.App Authorization Bypass in Push Notification API

WPMobile.App through 11.82 has an unauthenticated authorization bypass in the push notification API, allowing privileged access without valid credentials.

cat cve-2026-94541.json
Vendor
WPMobile.App
Product
WPMobile.App WordPress Plugin (versions up to and including 11.82)
CVSS
9.8
EPSS (exploit probability)
0.5%
Status
patched
Published

CVE-2026-94541 is a CVSS 9.8 critical authentication bypass in the WPMobile.App WordPress plugin, affecting all versions up to and including 11.82. The flaw exists in the plugin’s push notification API endpoint, which fails to properly verify caller authorization, allowing unauthenticated attackers to perform privileged actions.

Site administrators running WPMobile.App should update to a patched version through the WordPress admin dashboard. If an immediate update is not possible, deactivating the plugin removes the attack surface until the update can be applied.

Source: NVD.