CVE-2023-22702 MEDIUM

CVE-2023-22702: WordPress WPMobile.App — Android and iOS Mobile Application Plugin <= 11.13 is vulnerable to Cross Site Scripting (XSS)

Vendor Wpmobile.app
Product WPMobile.App — Android and iOS Mobile Application
Weakness CWE-79 · XSS
Published March 23, 2023
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.13 versions.

Explanation of Vulnerability in Simple Terms

02Summary

WPMobile.App versions 11.13 and earlier contain a cross-site scripting vulnerability that allows an attacker to inject malicious scripts into the application. An authenticated user must visit a crafted page or link for the attack to succeed. The vulnerability can affect the confidentiality, integrity, and availability of user data within the application's scope.

What an attacker can do

03Attacker Capabilities

Inject and execute malicious scripts in the app to steal data, modify content, or disrupt functionality.

Potential impact on your site

04Site Impact

Users' accounts and data are at risk if they visit attacker-controlled content while logged into the app.

Conditions required to exploit

05Prerequisites

Attacker needs a valid user account and must trick a user into visiting a malicious link or page.

Key dates

06Disclosure timeline

March 23, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE