Mobile builder

Mobile builder has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is Authentication Bypass Using An Alternate Path Or Channel, behind 1 of the records (100%).

The one issue recorded for Mobile builder has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Jarno Vos (jarnovos). Mobile builder is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.6.19.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Mobile builder vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2025-68860

Mobile builder <= 1.4.2 - Authentication Bypass

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Mobile builder banner
Latestv1.4.2

Mobile builder

Mobile Builder

Author

Mobile Builder

3.7(3)
74/100
Last Updated
2020-12-30 (6y ago)
Active Installs
50+
Downloads
16,898
Requires WP
5.3+
Requires PHP
7.0+
Tested up to
WP 5.6.19
Created
2020-02-19 (7y ago)

For the individuals who claim physical shops and designers, with OREO you have assortment prepared to-utilize E-commerce formats to make your portable store application. On the off chance that you had your online shops, OREO bolsters you to change over your present sites to portable store application effectively. Your store portable application will be found in both the App Store and Google Play Store. With OREO, your versatile application gives higher client experience contrasting with site on-portable. Your items will show up clear and can be zoom with no designing mistake. While you can control your store and requests of customers, your customers likewise can interface and remain mindful everything being equal and declarations of your stores in the event that they have your application on their mobiles. App source code

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C