CVE-2026-28038
Description
Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through <= 3.21.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in Ultimate Addons for WPBakery Page Builder up to 3.21.1 allows unauthenticated allows unauthenticated exploitation of access control.
Vulnerability
Overview
The plugin Ultimate Addons for WPBakery Page Builder (plugin slug: ultimate_vc_addons) suffers from a missing authorization vulnerability affecting versions from n/a through 3.21.1. The root cause is an incorrectly configured access control security level, which means certain functions or API endpoints lack proper authorization checks, allowing unauthorized action execution [1].
Exploitation
Details
Attackers can exploit this vulnerability without requiring authentication. The broken access control mechanism enables unprivileged users with lower privileges — or even unauthenticated visitors — to perform actions that should be restricted to higher-privileged roles such as administrators. This type of vulnerability is frequently used in mass-exploit campaigns, targeting thousands of WordPress sites regardless of size or popularity [1].
Impact
Successful exploitation could lead to unauthorized modification of plugin settings, content injection, or other administrative actions that compromise the site's integrity. The CVSS score of 6.5 (Medium) reflects the potential for significant impact with low attack complexity [1].
Mitigation
The vendor has released version 3.21.2 which resolves the issue. Users are strongly advised to update immediately. If updating to this patched version immediately. For those unable to update, applying available mitigation rules (e.g., from Patchstack) can block exploitation attempts until the update is applied [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=3.21.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.