Impact
The BM Content Builder plugin for WordPress contains a directory traversal flaw in the ux_cb_page_customize_save_layout_ajax() function, allowing authenticated users with Subscriber-level access or higher to read the contents of any file on the server. This vulnerability can expose sensitive configuration files, credentials, or internal documentation, compromising confidentiality but not integrity or availability directly.
Affected Systems
The issue affects the SeaTheme BM Content Builder plugin for WordPress in all releases prior to version 3.17.1. Users running any of those builds are at risk if their site includes a subscriber or higher user role.
Risk and Exploitability
With a CVSS score of 6.5 the threat is moderate; no EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. Practical exploitation requires a valid account with Subscriber or higher privileges and the ability to trigger the vulnerable AJAX endpoint. An attacker can then specify malicious file paths to retrieve arbitrary files, potentially gaining sensitive information about the hosting environment or application.
OpenCVE Enrichment