{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abm_content_builder_projectbm_content_builderwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bm_content_builder_project:bm_content_builder:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2025-1281"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BM Content Builder (\u003c 3.17.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe BM Content Builder plugin for WordPress contains an arbitrary file deletion vulnerability (CVE-2025-1281) resulting from insufficient file path validation within the \u003ccode\u003eux_cb_remove_layout_ajax()\u003c/code\u003e and \u003ccode\u003eux_cb_tools_export_ajax()\u003c/code\u003e functions. This vulnerability affects all plugin versions up to, and excluding, 3.17.1. Authenticated attackers with Subscriber-level privileges can trigger these functions to delete arbitrary files on the underlying web server. By deleting critical files such as \u003ccode\u003ewp-config.php\u003c/code\u003e, an attacker can force a WordPress site to enter its installation state, allowing them to gain control over the database, create a new administrative user, and achieve remote code execution. This represents a significant risk for WordPress environments using the BM Content Builder plugin.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the deletion of arbitrary files on the web server hosting the WordPress site. If configuration files are removed, attackers can compromise site integrity, elevate privileges to administrator, or gain remote code execution, leading to complete server takeover or data loss.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the BM Content Builder plugin to version 3.17.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit WordPress installations for unauthorized administrative account creation, which often occurs following the deletion of \u003ccode\u003ewp-config.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure that critical configuration files like \u003ccode\u003ewp-config.php\u003c/code\u003e have restrictive file system permissions that prevent the web server user from deleting them, where possible.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-22T08:34:26Z","date_published":"2026-09-22T08:34:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bm-content-builder-arbitrary-file-deletion/","summary":"An arbitrary file deletion vulnerability in the BM Content Builder plugin for WordPress allows authenticated attackers to delete critical system files, potentially facilitating remote code execution.","title":"Arbitrary File Deletion in BM Content Builder WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-bm-content-builder-arbitrary-file-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:bm_content_builder_project:bm_content_builder:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}