S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 4, 2025

CVE-2024-13888 Scanner

CVE-2024-13888 Scanner - Open Redirect vulnerability in WPMobile.App

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-13888
7.2
CVSShigh
Exploitable remotely over the internet · no authentication required.

The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WPMobile.Appby amauric
0
Updated Sep 10, 2026View on NVD →
Detail

The WPMobile.App plugin for WordPress is commonly used by website owners to transform their sites into mobile apps with convenience and efficiency. This plugin is ideal for web administrators who want to offer their users a mobile-friendly browsing experience without developing an app from scratch. Having a vast user base, it is often implemented by those managing WordPress sites looking for quick app solutions. It further eases developers’ work by handling the app's integration effortlessly. The plugin serves to bring a seamless, app-like interface to websites, aiding in better user retention and satisfaction. Being a plugin in the vast WordPress ecosystem, it's a popular choice for developers, designers, and website owners.

An Open Redirect vulnerability is an issue wherein an attacker can lead users to malicious sites through parameter manipulation. This occurs due to inadequate input validation of redirection URLs that the plugin processes. With WPMobile.App, the vulnerability is prevalent because of the insufficient validation of the 'redirect' parameter. Attackers can exploit this by tempting users into clicking crafted links which redirect them without proper checks. Because the vulnerability affects all versions of the plugin up to 56, it's a concern for many website operators using the plugin. Open Redirect issues are critical because they can facilitate further phishing attacks—exposing user information unintentionally.

The technical core of the vulnerability lies in the defective handling of URL redirects processed by the plugin. Specifically, when a URL is passed through the 'redirect' parameter, the plugin fails to authenticate the input source. Consequently, this failure allows unauthenticated requests to manipulate redirections. The vulnerable endpoint is often a publicly accessible script that directly manipulates the 'redirect' parameter. The inability to verify URL authenticity means a multitude of attack vectors are possible through crafted HTTP requests. This facilitates automated attacks where cyber actors craft URL patterns to reroute user traffic deceptively.

Exploiting this vulnerability could result in significant trust issues and security breaches. Primarily, users could be directed to phishing sites designed to steal credentials or sensitive information. Such a breach undermines user trust, impacting both the website's reputation and its user base. Additionally, an attacker could use this to redirect traffic to malicious downloads or exploit kits to compromise user devices. For businesses, this could mean financial loss, legal ramifications, and even long-term reputational damage. An exploitation of this sort might also fuel man-in-the-middle attacks, exacerbating security concerns for users navigating through compromised sites.

REFERENCES

Solution Advice
  • Update WPMobile.App to a version newer than 11.56 where the vulnerability is patched.
  • Implement input validation mechanisms on the 'redirect' parameter to ensure URL authenticity.
  • Educate users on recognizing phishing attempts and verify URLs before accessing them.
  • Review server settings to restrict redirects to trusted domains only.
  • Regularly audit plugins and third-party applications for potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-13888 Scanner - Open Redirect vulnerability in WPMobile.App | S4E