CVE-2025-0859: Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.6 via the templateviaurl() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0859?
CVE-2025-0859 has a medium severity level due to the potential for path traversal attacks.
How do I fix CVE-2025-0859?
To fix CVE-2025-0859, update the Post and Page Builder plugin to version 1.27.7 or later.
Who is affected by CVE-2025-0859?
CVE-2025-0859 affects all versions of the BoldGrid Post and Page Builder plugin up to and including version 1.27.6.
What type of vulnerability is CVE-2025-0859?
CVE-2025-0859 is classified as a path traversal vulnerability.
What access level is required to exploit CVE-2025-0859?
Authenticated attackers with Contributor-level access can exploit CVE-2025-0859.