CVE-2025-13029: Unknown Knowband Mobile App Builder
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users.
Affected products
- Unknown Knowband Mobile App Builder: before 3.0.0 (fixed in 3.0.0)
Published 2025-12-31. Last modified 2026-06-17.