CVE-2025-1279

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 862

Summary

CVE-2025-1279 is a vulnerability affecting the BM Content Builder plugin for WordPress. The issue arises from a missing capability check on the ux_cb_tools_import_item_ajax AJAX action, present in all versions up to 3.16.2.1. This flaw allows authenticated attackers, with Subscriber-level access and above, to manipulate data and update arbitrary options on the WordPress site. Successful exploitation of this vulnerability can result in privilege escalation, enabling attackers to elevate their user status to an administrative role. Consequently, attackers can gain unauthorized access to vulnerable WordPress sites and potentially cause significant damage.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share