VYPR
Medium severity6.5NVD Advisory· Published Mar 5, 2026· Updated Apr 23, 2026

CVE-2026-28038

CVE-2026-28038

Description

Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through <= 3.21.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Ultimate Addons for WPBakery Page Builder up to 3.21.1 allows unauthenticated allows unauthenticated exploitation of access control.

Vulnerability

Overview

The plugin Ultimate Addons for WPBakery Page Builder (plugin slug: ultimate_vc_addons) suffers from a missing authorization vulnerability affecting versions from n/a through 3.21.1. The root cause is an incorrectly configured access control security level, which means certain functions or API endpoints lack proper authorization checks, allowing unauthorized action execution [1].

Exploitation

Details

Attackers can exploit this vulnerability without requiring authentication. The broken access control mechanism enables unprivileged users with lower privileges — or even unauthenticated visitors — to perform actions that should be restricted to higher-privileged roles such as administrators. This type of vulnerability is frequently used in mass-exploit campaigns, targeting thousands of WordPress sites regardless of size or popularity [1].

Impact

Successful exploitation could lead to unauthorized modification of plugin settings, content injection, or other administrative actions that compromise the site's integrity. The CVSS score of 6.5 (Medium) reflects the potential for significant impact with low attack complexity [1].

Mitigation

The vendor has released version 3.21.2 which resolves the issue. Users are strongly advised to update immediately. If updating to this patched version immediately. For those unable to update, applying available mitigation rules (e.g., from Patchstack) can block exploitation attempts until the update is applied [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.