CVE-2026-28038: WordPress Ultimate Addons for WPBakery Page Builder plugin < 3.21.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.21.1.
Other sources
Missing Authorization vulnerability in BrainstormForce Ultimate Addons for WPBakery Page Builder ultimatevcaddons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through <= 3.21.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28038?
The severity of CVE-2026-28038 is medium, with a CVSS score of 6.5.
How do I fix CVE-2026-28038?
To fix CVE-2026-28038, update the WordPress Ultimate Addons for WPBakery Page Builder plugin to version 3.21.2 or later.
What is the impact of CVE-2026-28038?
CVE-2026-28038 allows unauthorized access due to incorrectly configured access control security levels.
Which versions are affected by CVE-2026-28038?
CVE-2026-28038 affects versions of the plugin from n/a through 3.21.1.
What kind of vulnerability is CVE-2026-28038?
CVE-2026-28038 is classified as a Broken Access Control vulnerability.