Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Dec 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastlinemedia
Fastlinemedia beaver Builder |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:fastlinemedia:beaver_builder:*:*:*:*:lite:wordpress:*:* | |
| Vendors & Products |
Fastlinemedia
Fastlinemedia beaver Builder |
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Tue, 09 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via the 'get_attachment_sizes' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the path and meta data of private attachments, which can be used to view the attachments. | |
| Title | Beaver Builder – WordPress Page Builder <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-09T14:15:13.367Z
Reserved: 2025-10-31T17:03:15.524Z
Link: CVE-2025-12558
Updated: 2025-12-09T14:15:09.044Z
Status : Analyzed
Published: 2025-12-09T16:17:34.243
Modified: 2025-12-11T17:44:04.650
Link: CVE-2025-12558
No data.
OpenCVE Enrichment
Updated: 2025-12-10T17:51:33Z