
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28038 is a Missing Authorization (Broken Access Control) vulnerability in the Ultimate Addons for WPBakery Page Builder WordPress plugin developed by Brainstorm Force. It affects all versions up to and including 3.21.1, and was reported by researcher João Pedro S Alcântara (Kinorth) on September 29, 2025, with public disclosure on March 2–5, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), requiring only low-level authenticated access (Subscriber role) to exploit (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the appropriate permissions before executing certain privileged actions. An authenticated attacker with at minimum Subscriber-level access can exploit incorrectly configured access control security levels to perform actions beyond their intended privilege scope. No user interaction is required, and the attack is conducted over the network with low complexity. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows an authenticated low-privileged user (e.g., a Subscriber) to perform unauthorized high-privileged actions within the WordPress site, resulting in a high integrity impact. Confidentiality and availability are not directly affected according to the CVSS scoring. In practice, this could allow attackers to modify site content, settings, or plugin configurations in ways normally restricted to administrators or editors, potentially enabling further compromise of the WordPress installation (Patchstack).
No active in-the-wild exploitation has been confirmed, and no exploit kits or weaponized code have been publicly identified. The EPSS score is approximately 0.017% (0.000170), indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that broken access control vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
ultimate_vc_addons that lack proper capability checks or nonce validation.wp-admin/admin-ajax.php or REST API endpoints associated with ultimate_vc_addons from low-privileged user accounts (Subscriber role).ultimate_vc_addons.The vendor Brainstorm Force has released version 3.21.2 of Ultimate Addons for WPBakery Page Builder, which patches this vulnerability. All users should update to version 3.21.2 or later immediately. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. If immediate updating is not possible, site administrators should restrict user registration or remove Subscriber-level accounts where not needed (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."