Skip to main content

CVE-2025-1280: WordPress BM Content Builder Path Traversal

CVE-2025-1280 is a directory traversal vulnerability in the BM Content Builder plugin for WordPress that allows authenticated attackers to read arbitrary files on the server. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-1280 Overview

CVE-2025-1280 is a directory traversal vulnerability in the BM Content Builder plugin for WordPress. The flaw exists in the ux_cb_page_customize_save_layout_ajax() function across all versions prior to 3.17.1. Authenticated users with Subscriber-level access or above can supply crafted path input to read arbitrary files on the server. Attackers commonly target files such as wp-config.php, which contains database credentials and secret keys.

Critical Impact

Authenticated attackers with minimal privileges can read arbitrary files on the WordPress host, exposing configuration secrets, credentials, and other sensitive data.

Affected Products

  • BM Content Builder plugin for WordPress (all versions up to and excluding 3.17.1)
  • WordPress sites bundling the BM Content Builder component through creative themes distributed via ThemeForest
  • Any deployment allowing Subscriber-level registration where the plugin is active

Discovery Timeline

  • 2026-09-22 - CVE-2025-1280 published to the National Vulnerability Database
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2025-1280

Vulnerability Analysis

The vulnerability resides in the ux_cb_page_customize_save_layout_ajax() AJAX handler exposed by BM Content Builder. The function accepts a filename or path parameter from an authenticated request and passes it to file read operations without normalization or allowlist validation. Because the AJAX endpoint enforces only the default WordPress authentication check, any user with Subscriber-level access or above can reach it. An attacker who supplies path traversal sequences such as ../../../../wp-config.php can retrieve file contents from outside the plugin directory.

The issue is classified as [CWE-22] Improper Limitation of a Pathname to a Restricted Directory. Exploitation yields read-only access, but files like wp-config.php contain database credentials, AUTH_KEY, SECURE_AUTH_KEY, and other secrets. These values enable follow-on attacks such as database compromise, cookie forgery, and privileged session takeover. WordPress installations that permit open registration expand the attacker population to anonymous internet users who can self-provision a Subscriber account.

Root Cause

The AJAX handler trusts user-supplied path input. It lacks canonicalization, realpath() validation, and a fixed base directory constraint. Capability checks are limited to authentication rather than a role check appropriate for file operations.

Attack Vector

Exploitation is remote and requires only a Subscriber account. The attacker sends an authenticated POST request to the WordPress admin-ajax.php endpoint targeting the vulnerable action. The path parameter contains traversal sequences pointing to sensitive server files.

No verified proof-of-concept code has been published. Refer to the Wordfence Vulnerability Report for additional technical context.

Detection Methods for CVE-2025-1280

Indicators of Compromise

  • POST requests to /wp-admin/admin-ajax.php where the action parameter targets the ux_cb_page_customize_save_layout_ajax handler
  • Request bodies containing path traversal patterns such as ../, ..%2f, or absolute paths referencing wp-config.php, /etc/passwd, or .env
  • Newly created Subscriber accounts followed by immediate AJAX activity against the BM Content Builder endpoint
  • Unexpected outbound authentication attempts using credentials matching those stored in wp-config.php

Detection Strategies

  • Inspect web server and WordPress access logs for the vulnerable AJAX action combined with encoded or literal traversal sequences
  • Deploy WAF signatures that block traversal patterns targeting the BM Content Builder AJAX action
  • Alert on read access to sensitive files by the PHP process outside of expected paths using host-level file integrity monitoring
  • Correlate low-privilege account activity with sensitive file access events to surface abuse of Subscriber roles

Monitoring Recommendations

  • Enable verbose logging on admin-ajax.php calls and forward to a central SIEM for retention and search
  • Track the plugin inventory across managed WordPress sites and alert on BM Content Builder versions below 3.17.1
  • Rotate any secrets stored in wp-config.php if exploitation is suspected and monitor database logins for anomalies

How to Mitigate CVE-2025-1280

Immediate Actions Required

  • Update the BM Content Builder plugin to version 3.17.1 or later on every WordPress instance
  • Disable open user registration or restrict the default new-user role away from Subscriber where feasible
  • Audit existing Subscriber accounts and remove unused or suspicious accounts
  • Rotate WordPress salts, database credentials, and API keys stored in wp-config.php if compromise is suspected

Patch Information

The vendor addressed the directory traversal in BM Content Builder version 3.17.1. Sites relying on bundled installations through creative WordPress themes distributed via ThemeForest should obtain the fixed version from the theme author. See the ThemeForest Creative WordPress Theme listing for vendor distribution details.

Workarounds

  • Deactivate the BM Content Builder plugin until the update to 3.17.1 can be applied
  • Add a WAF rule that blocks requests to admin-ajax.php where the action targets ux_cb_page_customize_save_layout_ajax and the payload includes traversal sequences
  • Restrict filesystem permissions so the PHP worker account cannot read files outside the WordPress document root
bash
# Example ModSecurity rule blocking traversal against the vulnerable AJAX action
SecRule REQUEST_URI "@contains /wp-admin/admin-ajax.php" \
    "chain,phase:2,deny,status:403,id:1002025,\
     msg:'CVE-2025-1280 BM Content Builder path traversal attempt'"
    SecRule ARGS "@rx (ux_cb_page_customize_save_layout_ajax)" \
        "chain"
        SecRule ARGS "@rx (\.\./|\.\.%2f|wp-config\.php)" "t:lowercase,t:urlDecodeUni"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.