CVE-2026-103421 WPMobile.App 存储型跨站脚本漏洞
影响未授权攻击者可注入恶意脚本,在用户访问页面时执行
WordPress 插件 WPMobile.App(Android 与 iOS App Builder)存在存储型跨站脚本漏洞。由于对 REQUEST_URI(/android_json/search/ 后的路径段)参数输入过滤与输出转义不足,未认证攻击者可注入任意 Web 脚本。该脚本会在用户访问被注入页面时执行。
影响范围
影响该插件所有版本,直至并包括 11.84。
漏洞详情
漏洞类型为存储型跨站脚本(XSS),成因是插件对 /android_json/search/ 路径段参数缺乏充分的输入清理与输出转义。攻击者可将恶意脚本注入页面并持久化存储,当其他用户浏览该页面时脚本在浏览器中执行。利用需将应用内容模式配置为 webview(即 speed 选项未设为 1),该模式仍受支持但已非默认。
利用条件与风险
利用前提是站点使用 webview 内容模式,攻击者无需认证即可注入脚本,可能导致会话劫持、页面篡改等风险。
修复建议
建议升级至 11.84 之后的修复版本;若暂无补丁,可临时将内容模式切换为 speed 模式(speed=1)以缓解,或对相关参数进行严格过滤与转义。
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘REQUEST_URI (path segment after /android_json/search/)’ parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app’s content mode to be configured as ‘webview’ (i.e., the ‘speed’ option is not set to ‘1’), which is a supported and still-shipped mode, though no longer the default.