Filtered by vendor Ckp267
Subscriptions
Filtered by product Maxiblocks Builder
Subscriptions
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-2028 | 2 Ckp267, Wordpress | 2 Maxiblocks Builder, Wordpress | 2026-04-28 | 5.3 Medium |
| The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi_remove_custom_image_size' AJAX action in all versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files in the wp-content/uploads directory, including files uploaded by other users and administrators. | ||||
Page 1 of 1.