๐Ÿ” CVE Alert

CVE-2026-103694

UNKNOWN 0.0

Mobile builder <= 1.4.2 - Subscriber+ Privilege Escalation to Admin

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Mobile builder WordPress plugin through 1.4.2 does not properly restrict which user meta keys a logged-in user can update through one of its REST routes, allowing any user with a self-registered account, such as a customer, to grant themselves the administrator role.

Vendor unknown
Product mobile builder
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown mobile builder

Be the first to know when new unknown vulnerabilities affecting unknown mobile builder are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Mobile builder
0 โ‰ค 1.4.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5d087920-26f3-4c71-bfcb-ae9a70cc407f/

Credits

Raphael P. Cigana WPScan