Impact
The vulnerability resides in the Ultimate Addons for WPBakery Page Builder WordPress plugin. Prior to version 3.21.4 the plugin fails to perform a capability or nonce check before executing the delete‑bsf‑fonts action, which is a CWE‑73 External Control of File Name or Path flaw. This omission allows an unauthenticated attacker to issue a single request that permanently removes all custom‑uploaded icon font packs from the site. The action has no impact on code execution or data confidentiality, but it does cause irreversible loss of site assets that may affect page rendering and design integrity.
Affected Systems
Any WordPress installation using Ultimate Addons for WPBakery Page Builder versions older than 3.21.4 is vulnerable. The plugin is distributed by Ultimate Addons for WPBakery Page Builder and is commonly found installed on sites that rely on custom icon fonts for page design.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% suggests a low exploitation probability at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request directed at the delete‑bsf‑fonts endpoint, exploiting the missing capability and nonce checks. Because no authentication is required, an attacker can trigger the deletion from outside the site’s administration interface, making remediation a priority.
OpenCVE Enrichment