
CVE-2026-2028 The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi_remove_custom_imag… https://www.cve.org/CVERecord?id=CVE-2026-2028
Post summary
The CVE-2026-2028 vulnerability in the MaxiBlocks Builder WordPress plugin permits arbitrary deletion of media files because the plugin fails to validate file ownership before removal.
