Executive brief
The BM Content Builder plugin for WordPress allows authenticated users with basic subscriber permissions to read arbitrary files from the server through a directory traversal vulnerability. An attacker could exploit this to access sensitive configuration files, database credentials, or other confidential data stored on the web server.
Technical details
The vulnerability exists in the ux_cb_page_customize_save_layout_ajax() function and permits directory traversal attacks. Exploitation requires authentication as a Subscriber or higher privilege level and network access to the WordPress application. Successful exploitation allows arbitrary file read access on the affected server.
Affected products
- BM Content Builder BM Content Builder up to 3.17.1
Timeline
- 2025-09-22: disclosed