Impact
The BM Content Builder plugin for WordPress contains a missing capability check on the ux_cb_tools_import_item_ajax AJAX action. This flaw allows any authenticated user with Subscriber-level access or higher to modify arbitrary WordPress options. In practice, attackers could change the default role for new registrations to administrator and enable user registration, giving them a route to gain administrative privileges on the site.
Affected Systems
The vulnerability affects SeaTheme’s BM Content Builder plugin in all versions up to and including 3.16.2.1. Users running any of these versions should verify their installation.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is considered high severity. The EPSS score is less than 1 %, indicating a low probability of exploitation in the current environment, and it is not listed in the CISA KEV catalog. The attack requires a valid authenticated account with at least Subscriber rights, but once access is obtained an attacker can perform privilege escalation by manipulating WordPress options through the exposed AJAX endpoint.
OpenCVE Enrichment
EUVD