PT-2025-54282 · WordPress · Mobile App Builder
Khaled Alenazi
·
Published
2025-12-31
·
Updated
2026-01-05
·
CVE-2025-13029
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Knowband Mobile App Builder WordPress plugin versions prior to 3.0.0
Description
The plugin lacks proper authorization checks when deleting users through its REST API. This allows unauthenticated attackers to delete any user. The vulnerable API endpoint allows for arbitrary user deletion without authentication. The affected API endpoint is used for user management.
Recommendations
Update to version 3.0.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mobile App Builder