Security Advisory

CVE-2025-13029

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-31 06:00:03
Last updated 2026-01-02 14:37:20
Assigner WPScan
State PUBLISHED

Description

The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users.