Wpmobilepack develops a WordPress mobile application plugin that extends WordPress functionality to mobile platforms, with observed vulnerabilities concentrating in the WordPress Mobile Pack product itself. The durable signal centers on application-level input and session-handling weaknesses, including cross-site request forgery and sensitive information exposure, which are characteristic of web-to-mobile bridge plugins. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpmobilepack over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5337MEDIUM The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attackers to obtain sensitive informa | Aug 29, 2014 | 5.0 | 35 | NO | YES |
CVE-2023-37391MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in WPMobilePack.Com WordPress Mobile Pack – Mobile Plugin for Progressive Web Apps & Hybrid Mobile Apps plugin <= 3.4.1 versions. | Jul 11, 2023 | 6.5 | 21 | NO | NO |
CVE-2015-9269HIGH The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress allows remote attackers to obtain sensitive information becau | Oct 1, 2018 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmobilepack.
Media articles that mention a CVE ID that affects a product developed by Wpmobilepack — matched by CVE ID, not by vendor name.