Skip to main content

Threat intelligence

Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion

CVE-2026-15382 · Ultimate_VC_Addons

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Ultimate_VC_Addons at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion
Affected software
Ultimate_VC_Addons(Plugin)
Affected versions
  • < 3.21.4
Authentication
Unauthenticated
Vulnerability type
Other
Published
10 July 2026
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory 45b81d01-1ecc-4881-9e21-48b8fcb732ea). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Ultimate_VC_Addons version against this catalog when the Defence plugin is connected to your WordPress site.