Arbitrary File Deletion Vulnerability in MaxiBlocks Builder for WordPress
CVE-2026-2028

5.3MEDIUM

What is CVE-2026-2028?

The MaxiBlocks Builder plugin for WordPress is susceptible to a serious flaw that allows authenticated attackers with Author-level access or higher to delete arbitrary media files from the wp-content/uploads directory. This vulnerability stems from inadequate validation of file ownership during the execution of the 'maxi_remove_custom_image_size' AJAX action. Consequently, it poses a risk to files uploaded by other users and administrators, enabling unauthorized file deletion across different user accounts.

Affected Version(s)

MaxiBlocks Builder | 17,000+ Design Assets, Patterns, Icons & Starter Sites 0 <= 2.1.8

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Teerachai Somprasong
.