Directory Traversal Vulnerability in BM Content Builder Plugin for WordPress
CVE-2025-1280

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2026

What is CVE-2025-1280?

The BM Content Builder plugin for WordPress is affected by a directory traversal vulnerability through the ux_cb_page_customize_save_layout_ajax() function. This issue allows authenticated users with Subscriber-level access and above to exploit the vulnerability and access sensitive files on the server, risking the exposure of confidential information. All versions of the plugin prior to 3.17.1 are impacted, highlighting the need for immediate updates or security measures to mitigate potential attacks.

Affected Version(s)

BM Content Builder 0 < 3.17.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tonn
.