BM Content Builder [bm-builder] <= 3.16.3 (unfixed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder bm-builder allows Path Traversal.This issue affects BM Content Builder: from n/a through <= 3.16.3.
- Affected:
- up to 3.16.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-69055 on NVD →
BM Content Builder < 3.16.3.3 - Authenticated (Contributor+) Arbitrary File Download
medium
The BM Content Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and excluding, 3.16.3.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 6.5
- Affected:
- up to 3.16.3.3
- Fixed in:
- 3.16.3.3
- Disclosed:
- Dec 31, 2025
CVE-2025-69055 on NVD →
BM Content Builder [bm-builder] < 3.16.3.3
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder allows Path Traversal. This issue affects BM Content Builder: from n/a through n/a.
- Affected:
- up to 3.16.3.3
- Fixed in:
- 3.16.3.3
- Disclosed:
- Sep 26, 2025
CVE-2025-59002 on NVD →
BM Content Builder < 3.16.3.3 - Authenticated (Contributor+) Arbitrary File Deletion
high
The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to 3.16.3.3 (exclusive). This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily...
- CVSS:
- 8.1
- Affected:
- up to 3.16.3.3
- Fixed in:
- 3.16.3.3
- Disclosed:
- Sep 23, 2025
CVE-2025-59002 on NVD →
BM Content Builder <= 3.16.2.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via ux_cb_page_options_save
medium
The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'ux_cb_page_options_save' function in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arb...
- CVSS:
- 6.4
- Affected:
- up to 3.16.2.1
- Fixed in:
- 3.16.3
- Disclosed:
- Jun 5, 2025
CVE-2025-1777 on NVD →
BM Content Builder <= 3.16.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
high
The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ux_cb_tools_import_item_ajax AJAX action in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with...
- CVSS:
- 8.8
- Affected:
- up to 3.16.2.1
- Fixed in:
- 3.16.3
- Disclosed:
- Apr 24, 2025
CVE-2025-1279 on NVD →
BM Content Builder [bm-builder] < 3.16.3
unknown
- Affected:
- up to 3.16.3
- Fixed in:
- 3.16.3
CVE-2025-1279 on NVD →
BM Content Builder [bm-builder] < 3.16.3
unknown
- Affected:
- up to 3.16.3
- Fixed in:
- 3.16.3
CVE-2025-1777 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database