CVE-2026-15382

Summary

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.

Affected Software

VendorProductVersion RangeStatus
UnknownUltimate Addons for WPBakery Page Builder0 < 3.21.4affected

Weaknesses

  • CWE-73 External Control of File Name or Path

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

References