CVE-2026-28038: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-28038 is a Missing Authorization (Broken Access Control) vulnerability in the Ultimate Addons for WPBakery Page Builder WordPress plugin developed by Brainstorm Force. It affects all versions up to and including 3.21.1, and was reported by researcher João Pedro S Alcântara (Kinorth) on September 29, 2025, with public disclosure on March 2–5, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), requiring only low-level authenticated access (Subscriber role) to exploit (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the appropriate permissions before executing certain privileged actions. An authenticated attacker with at minimum Subscriber-level access can exploit incorrectly configured access control security levels to perform actions beyond their intended privilege scope. No user interaction is required, and the attack is conducted over the network with low complexity. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an authenticated low-privileged user (e.g., a Subscriber) to perform unauthorized high-privileged actions within the WordPress site, resulting in a high integrity impact. Confidentiality and availability are not directly affected according to the CVSS scoring. In practice, this could allow attackers to modify site content, settings, or plugin configurations in ways normally restricted to administrators or editors, potentially enabling further compromise of the WordPress installation (Patchstack).

Exploitability

No active in-the-wild exploitation has been confirmed, and no exploit kits or weaponized code have been publicly identified. The EPSS score is approximately 0.017% (0.000170), indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that broken access control vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Ultimate Addons for WPBakery Page Builder plugin version 3.21.1 or earlier using tools like WPScan or by inspecting plugin metadata in publicly accessible readme.txt files.
  2. Obtain low-privileged access: Register or obtain credentials for a Subscriber-level account on the target WordPress site (e.g., via open registration if enabled).
  3. Identify unprotected endpoints: Enumerate plugin-specific AJAX actions or REST API endpoints exposed by ultimate_vc_addons that lack proper capability checks or nonce validation.
  4. Send unauthorized request: Craft and submit an authenticated HTTP request (with valid Subscriber session cookies/nonce) to the vulnerable endpoint, invoking a privileged action such as modifying plugin settings or site content.
  5. Achieve unauthorized modification: The server processes the request without verifying the user's privilege level, resulting in unauthorized changes to site integrity (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to wp-admin/admin-ajax.php or REST API endpoints associated with ultimate_vc_addons from low-privileged user accounts (Subscriber role).
  • Logs: Unexpected plugin setting changes or content modifications recorded in WordPress audit logs (if an audit plugin is installed) attributed to Subscriber-level users.
  • File System: Unexplained changes to plugin configuration files or WordPress options table entries related to ultimate_vc_addons.
  • Network: Repeated authenticated requests from the same IP to plugin-specific AJAX actions, potentially indicating automated exploitation attempts.

Mitigation and workarounds

The vendor Brainstorm Force has released version 3.21.2 of Ultimate Addons for WPBakery Page Builder, which patches this vulnerability. All users should update to version 3.21.2 or later immediately. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. If immediate updating is not possible, site administrators should restrict user registration or remove Subscriber-level accounts where not needed (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management