CVE-2025-1280: BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Read
The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the uxcbpagecustomizesavelayoutajax() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BM Content Builderto a version that resolves this vulnerability.Fixed in 3.17.1
Event History
Frequently Asked Questions
Which users could exploit this issue?
Any authenticated WordPress user with at least the Subscriber role can exploit it. The attacker does not need elevated administrative permissions.
What can an attacker obtain through exploitation?
An attacker can read arbitrary files from the server through directory traversal. Exposed files may contain sensitive information.
Which plugin versions are affected?
BM Content Builder versions earlier than 3.17.1 are affected. Version 3.17.1 and later are not identified as affected by the provided information.