MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 14 h ago, last 14 h ago, peak #5

WordPress app builder plugin hit by stored XSS flaw

Original: 🚨 EUVD-2026-91951 πŸ“Š Score: 5.4/10 (CVSS v3.1) πŸ“¦ Product: WPMobile.App – Android and iOS App Builder 🏒 Vendor: amauric πŸ“…

A medium-severity vulnerability, tracked as EUVD-2026-91951 with a CVSS score of 5.4, has been disclosed in the WPMobile.App – Android and iOS App Builder WordPress plugin by vendor amauric. The flaw is a stored cross-site scripting issue reachable via the REQUEST_URI parameter, meaning attackers could inject malicious scripts that persist and run in visitors' browsers. Administrators running the plugin are advised to check for an updated version.

Why now: A newly published vulnerability disclosure for a widely used type of WordPress plugin prompts site admins to check whether they are affected.

WPMobile.AppamauricWordPressEUVD-2026-91951

Open on mastodon β†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/835686