Junglewise Threat Intelligence

CVE-2025-1281: BM Content Builder arbitrary file deletion in layout removal

CVE-2025-1281 · Severity: high · CVSS 8.8 · Published 2026-09-22

Executive brief

The BM Content Builder WordPress plugin is vulnerable to arbitrary file deletion due to insufficient path validation, affecting users with Subscriber-level access or higher. An attacker can delete critical files like wp-config.php to compromise the entire WordPress installation and gain remote code execution. This vulnerability impacts all versions before 3.17.1.

Technical details

The vulnerability exists in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions, which fail to properly validate file paths before deletion. Authenticated attackers with Subscriber-level privileges can exploit this via direct AJAX requests to delete arbitrary files on the server. Successful exploitation typically leads to remote code execution through deletion of sensitive configuration or core files.

Affected products

  • BM Content Builder BM Content Builder before 3.17.1

Timeline

  • 2025-09-22: disclosed

References

Related threats