Arbitrary File Deletion Vulnerability in MaxiBlocks Builder for WordPress
CVE-2026-2028
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 April 2026
What is CVE-2026-2028?
The MaxiBlocks Builder plugin for WordPress is susceptible to a serious flaw that allows authenticated attackers with Author-level access or higher to delete arbitrary media files from the wp-content/uploads directory. This vulnerability stems from inadequate validation of file ownership during the execution of the 'maxi_remove_custom_image_size' AJAX action. Consequently, it poses a risk to files uploaded by other users and administrators, enabling unauthorized file deletion across different user accounts.
Affected Version(s)
MaxiBlocks Builder | 17,000+ Design Assets, Patterns, Icons & Starter Sites 0 <= 2.1.8