plugin

Bm Builder Vulnerabilities

8 known security issues reported for the Bm Builder WordPress plugin. Most recent disclosed Jan 22, 2026.

2 high 2 medium

Running Bm Builder on your site? Check whether your installed version is affected.

Scan your site free

BM Content Builder [bm-builder] <= 3.16.3 (unfixed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder bm-builder allows Path Traversal.This issue affects BM Content Builder: from n/a through <= 3.16.3.

Affected:
up to 3.16.3
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-69055 on NVD →

BM Content Builder < 3.16.3.3 - Authenticated (Contributor+) Arbitrary File Download

medium

The BM Content Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and excluding, 3.16.3.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
6.5
Affected:
up to 3.16.3.3
Fixed in:
3.16.3.3
Disclosed:
Dec 31, 2025

CVE-2025-69055 on NVD →

BM Content Builder [bm-builder] < 3.16.3.3

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder allows Path Traversal. This issue affects BM Content Builder: from n/a through n/a.

Affected:
up to 3.16.3.3
Fixed in:
3.16.3.3
Disclosed:
Sep 26, 2025

CVE-2025-59002 on NVD →

BM Content Builder < 3.16.3.3 - Authenticated (Contributor+) Arbitrary File Deletion

high

The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to 3.16.3.3 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily...

CVSS:
8.1
Affected:
up to 3.16.3.3
Fixed in:
3.16.3.3
Disclosed:
Sep 23, 2025

CVE-2025-59002 on NVD →

BM Content Builder <= 3.16.2.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via ux_cb_page_options_save

medium

The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'ux_cb_page_options_save' function in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arb...

CVSS:
6.4
Affected:
up to 3.16.2.1
Fixed in:
3.16.3
Disclosed:
Jun 5, 2025

CVE-2025-1777 on NVD →

BM Content Builder <= 3.16.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

high

The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ux_cb_tools_import_item_ajax AJAX action in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with...

CVSS:
8.8
Affected:
up to 3.16.2.1
Fixed in:
3.16.3
Disclosed:
Apr 24, 2025

CVE-2025-1279 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database