CVE-2026-27067

9.1

Syarif Mobile · Mobile App Editor

An unrestricted file upload vulnerability in the Mobile App Editor plugin allows authenticated users with administrative privileges to upload arbitrary files, potentially leading to remote code execution.

Executive summary

The Mobile App Editor plugin for WordPress is vulnerable to arbitrary file uploads, posing a critical risk of remote code execution for sites using versions 1.3.1 and earlier.

Vulnerability

This vulnerability is classified as CWE-434: Unrestricted Upload of File with Dangerous Type. It requires an attacker to have administrative-level privileges to interact with the vulnerable upload function.

Business impact

Successful exploitation allows an attacker to upload a web shell to the server, resulting in full control over the affected web application. Given the CVSS score of 9.1, this represents a critical risk of total system compromise, unauthorized data access, and potential lateral movement within the network.

Remediation

Immediate Action: As no patched version is currently available, administrators should immediately deactivate and uninstall the Mobile App Editor plugin until a secure update is released by the vendor.

Proactive Monitoring: Review web server and WordPress audit logs for unusual file creation events in the uploads directory, particularly files with executable extensions.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized file uploads and monitor for suspicious traffic patterns targeting administrative endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability and the lack of an available security patch, immediate removal of the affected software is the only viable path to eliminate risk. Organizations should prioritize decommissioning the plugin to prevent potential malicious file execution and subsequent server takeover.