Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Knowband
Knowband mobile App Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Knowband
Knowband mobile App Builder Wordpress Wordpress wordpress |
Fri, 02 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 31 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users. | |
| Title | Knowband Mobile App Builder for wooCommerce < 3.0.0 – Unauthenticated Arbitrary User Deletion | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-01-02T14:37:20.664Z
Reserved: 2025-11-11T15:13:42.244Z
Link: CVE-2025-13029
Updated: 2026-01-02T14:20:56.150Z
Status : Deferred
Published: 2025-12-31T06:15:40.270
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13029
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:18:02Z
No weakness.