Executive brief
The BM Content Builder WordPress plugin is vulnerable to arbitrary file deletion due to insufficient path validation, affecting users with Subscriber-level access or higher. An attacker can delete critical files like wp-config.php to compromise the entire WordPress installation and gain remote code execution. This vulnerability impacts all versions before 3.17.1.
Technical details
The vulnerability exists in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions, which fail to properly validate file paths before deletion. Authenticated attackers with Subscriber-level privileges can exploit this via direct AJAX requests to delete arbitrary files on the server. Successful exploitation typically leads to remote code execution through deletion of sensitive configuration or core files.
Affected products
- BM Content Builder BM Content Builder before 3.17.1
Timeline
- 2025-09-22: disclosed