SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15382

MEDIUM · CVSS 6.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Ultimate Addons for WPBakery Page Builder plugin for WordPress prior to version 3.21.4 is vulnerable to unauthorized deletion of custom-uploaded icon font packs due to the absence of capability or nonce checks. This flaw allows unauthenticated attackers to permanently remove all custom icon fonts from a site with a single request, potentially disrupting the site's design and user experience. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-15382
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%
WordPress

Original NVD Description

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.