CVE-2025-1777: BM Content Builder <= 3.16.2.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via ux_cb_page_options_save
The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'uxcbpageoptionssave' function in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1777?
CVE-2025-1777 is classified as a high severity vulnerability due to the potential for unauthorized modification of data.
How do I fix CVE-2025-1777?
To fix CVE-2025-1777, update the BM Content Builder plugin to version 3.16.2.2 or later where the missing capability check has been resolved.
Who is affected by CVE-2025-1777?
All users of the BM Content Builder plugin for WordPress up to and including version 3.16.2.1 are affected by CVE-2025-1777.
What type of attacks can exploit CVE-2025-1777?
CVE-2025-1777 can be exploited by authenticated attackers, including subscribers, to make unauthorized data changes.
What function is vulnerable in CVE-2025-1777?
The missing capability check occurs in the 'ux_cb_page_options_save' function of the BM Content Builder plugin, leading to the vulnerability.