CVE-2026-15382

Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.


We have discovered 116,345 live websites that are affected by CVE-2026-15382.

Run a Free Instant Scan




Affected Software

Product  Visual Composer Ultimate Addons
Category Widgets
Vulnerable Domains116,345 live websites (100% of Visual Composer Ultimate Addons install base)
Vulnerable Versions
  • from 0 through 3.21.4
Vulnerable Versions Count87 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-73 External Control of File Name or Path



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Trần Tiến (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-15382
United States30,831 websites



Germany14,588 websites
France6,774 websites
Italy6,314 websites
GB5,516 websites
Spain4,703 websites
Netherlands4,232 websites
Australia2,814 websites
Denmark2,731 websites
Russia2,678 websites

Website Distribution by TLD

Number of websites using CVE-2026-15382
.com45,707 websites
.de9,391 websites
.it4,638 websites
.org4,529 websites
.nl3,796 websites
.co.uk3,523 websites
.fr2,790 websites
.com.au2,678 websites
.dk2,253 websites
.ru2,116 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15382

Top websites that are affected by CVE-2026-15382. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**,***
*******.de Germany**,***
*********.*******.*****.edu United States**,***
****************************.com United States**,***
*****.tv United States**,***
**********.com United States**,***
********.com United States**,***
******************.com United States**,***
******.sk Slovakia**,***
*****.com United States**,***
See full domain list

FAQ

CVE-2026-15382 is External Control of File Name or Path in Visual Composer Ultimate Addons
A total of 116,345 websites have been identified as vulnerable to CVE-2026-15382, based on global website indexing conducted by WebTechSurvey.
The Visual Composer Ultimate Addons is affected by the CVE-2026-15382 vulnerability.
Visual Composer Ultimate Addons versions up to 3.21.4 are vulnerable to CVE-2026-15382.
CVE-2026-15382 is resolved in version 3.21.4 of Visual Composer Ultimate Addons.