CVE-2026-2028

Source
https://cve.org/CVERecord?id=CVE-2026-2028
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2028.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-2028
Published
2026-04-24T03:27:06.728Z
Modified
2026-08-07T11:50:41.528112503Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Maxi Blocks <= 2.1.8 - Missing Authorization to Authenticated (Author+) Media File Deletion via 'old_media_src' Parameter
Details

The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxiremovecustomimagesize' AJAX action in all versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files in the wp-content/uploads directory, including files uploaded by other users and administrators.

Database specific
{
    "cna_assigner": "Wordfence",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2028.json"
}
References

Affected packages

Git / github.com/maxi-blocks/maxi-blocks

Affected ranges

Type
GIT
Repo
https://github.com/maxi-blocks/maxi-blocks
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.8"
        }
    ]
}

Affected versions

1.*
1.8.0
v.*
v.1.6.1
v1.*
v1.5.1
v1.5.2
v1.5.3
v1.5.5
v1.5.6
v1.5.7
v1.5.8
v1.6.0
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.2
v1.9.7
v1.9.8
v1.9.9
v2.*
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.9
v2.1.0
v2.1.2
v2.1.4
v2.1.6
v2.1.7
v2.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2028.json"