Amauri Wpmobile.App vulnerabilities
8 known vulnerabilities affecting amauri/wpmobile.app.
Total CVEs
8
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH2MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2024-35694P1MEDIUMCVSS 6.1ExploitedPoCfixed in 11.42≤ 11.412024-06-08
CVE-2024-35694 [MEDIUM] CWE-79 CVE-2024-35694: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.41.
nvd
CVE-2024-13888P3MEDIUMCVSS 6.1PoCfixed in 11.572025-02-20
CVE-2024-13888 [MEDIUM] CWE-601 CVE-2024-13888: The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and incl
The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them i
nvd
CVE-2025-62074P4HIGHCVSS 7.1≤ 11.712025-11-06
CVE-2025-62074 [HIGH] CWE-79 CVE-2025-62074: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.71.
nvd
CVE-2024-47349P4HIGHCVSS 7.1≤ 11.502024-10-06
CVE-2024-47349 [HIGH] CWE-79 CVE-2024-47349: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.50.
nvd
CVE-2023-22702P4MEDIUMCVSS 5.4fixed in 11.142023-03-23
CVE-2023-22702 [MEDIUM] CWE-79 CVE-2023-22702: Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.13 versions.
nvd
CVE-2024-43933P4MEDIUMCVSS 4.3≤ 11.482024-10-31
CVE-2024-43933 [MEDIUM] CWE-79 CVE-2024-43933: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja allows Stored XSS.This issue affects WPMobile.App: from n/a through <= 11.48.
nvd
CVE-2023-28932P4MEDIUMCVSS 4.8≤ 11.202023-05-10
CVE-2023-28932 [MEDIUM] CWE-79 CVE-2023-28932: Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Androi
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.20 versions.
nvd
CVE-2023-26010P4MEDIUMCVSS 4.8fixed in 11.192023-05-04
CVE-2023-26010 [MEDIUM] CWE-79 CVE-2023-26010: Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App plugin <= 11.18 versi
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App plugin <= 11.18 versions.
nvd