CVE-2025-1279
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-1279 is a vulnerability affecting the BM Content Builder plugin for WordPress. The issue arises from a missing capability check on the ux_cb_tools_import_item_ajax AJAX action, present in all versions up to 3.16.2.1. This flaw allows authenticated attackers, with Subscriber-level access and above, to manipulate data and update arbitrary options on the WordPress site. Successful exploitation of this vulnerability can result in privilege escalation, enabling attackers to elevate their user status to an administrative role. Consequently, attackers can gain unauthorized access to vulnerable WordPress sites and potentially cause significant damage.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.