PT-2025-54282 · WordPress · Mobile App Builder

Khaled Alenazi

·

Published

2025-12-31

·

Updated

2026-01-05

·

CVE-2025-13029

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Knowband Mobile App Builder WordPress plugin versions prior to 3.0.0
Description The plugin lacks proper authorization checks when deleting users through its REST API. This allows unauthenticated attackers to delete any user. The vulnerable API endpoint allows for arbitrary user deletion without authentication. The affected API endpoint is used for user management.
Recommendations Update to version 3.0.0 or later.

Exploit

Fix

Related Identifiers

CVE-2025-13029

Affected Products

Mobile App Builder