CyberRota Analysis
AI-GeneratedThe Ultimate Addons for WPBakery Page Builder plugin for WordPress prior to version 3.21.4 is vulnerable to unauthorized deletion of custom-uploaded icon font packs due to the absence of capability or nonce checks. This flaw allows unauthenticated attackers to permanently remove all custom icon fonts from a site with a single request, potentially disrupting the site's design and user experience. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.