PT-2025-53799 · WordPress · Mobile Builder

Jarno Vos

+1

·

Published

2025-12-29

·

Updated

2025-12-31

·

CVE-2025-68860

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mobile Builder versions through 1.4.2
Description Mobile Builder is susceptible to an authentication bypass, allowing authentication abuse. This allows attackers to gain full control without valid credentials. The issue concerns a completely broken authentication mechanism within the WordPress Mobile Builder plugin, enabling trivial remote access.
Recommendations Update Mobile Builder to a version later than 1.4.2.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2025-68860

Affected Products

Mobile Builder