PT-2025-54282 · WordPress · Mobile App Builder

·

CVE-2025-13029

·

Published

2025-12-31

·

Updated

2026-01-05

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Knowband Mobile App Builder WordPress plugin versions prior to 3.0.0
Description The plugin lacks proper authorization checks when deleting users through its REST API. This allows unauthenticated attackers to delete any user. The vulnerable API endpoint allows for arbitrary user deletion without authentication. The affected API endpoint is used for user management.
Recommendations Update to version 3.0.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-13029

Affected Products

Mobile App Builder