PatchSiren

Mobile builder CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Mobile builder CVE published 2026-10-11

CVE-2026-103695

The Mobile builder WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This vulnerability can lead to potential unauthorized access to sensitive data, disruption of WordPress plugin functionality, and lateral movement within compromised WordPress environments. Defenders should assess ex [truncated]

Review Mobile builder CVE published 2026-10-11

CVE-2026-103694

The Mobile builder WordPress plugin through 1.4.2 does not properly restrict which user meta keys a logged-in user can update through one of its REST routes, allowing any user with a self-registered account, such as a customer, to grant themselves the administrator role. This vulnerability allows self-registered users to potentially escalate privileges, increasing the risk of administrator role compromise [truncated]