HomeDefault status
unaffected
Any version before 3.0.0
affected
Description
The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users.
Problem types
Product status
Any version before 3.0.0
Credits
Khaled Alenazi (Nxploited)
WPScan
References
wpscan.com/...rability/22344534-cd36-4817-b683-c0af55759e01/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.