<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:bm_content_builder_project:bm_content_builder:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3abm_content_builder_projectbm_content_builderwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 08:34:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3abm_content_builder_projectbm_content_builderwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Deletion in BM Content Builder WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-bm-content-builder-arbitrary-file-deletion/</link><pubDate>Tue, 22 Sep 2026 08:34:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-bm-content-builder-arbitrary-file-deletion/</guid><description>An arbitrary file deletion vulnerability in the BM Content Builder plugin for WordPress allows authenticated attackers to delete critical system files, potentially facilitating remote code execution.</description><content:encoded><![CDATA[<p>The BM Content Builder plugin for WordPress contains an arbitrary file deletion vulnerability (CVE-2025-1281) resulting from insufficient file path validation within the <code>ux_cb_remove_layout_ajax()</code> and <code>ux_cb_tools_export_ajax()</code> functions. This vulnerability affects all plugin versions up to, and excluding, 3.17.1. Authenticated attackers with Subscriber-level privileges can trigger these functions to delete arbitrary files on the underlying web server. By deleting critical files such as <code>wp-config.php</code>, an attacker can force a WordPress site to enter its installation state, allowing them to gain control over the database, create a new administrative user, and achieve remote code execution. This represents a significant risk for WordPress environments using the BM Content Builder plugin.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the deletion of arbitrary files on the web server hosting the WordPress site. If configuration files are removed, attackers can compromise site integrity, elevate privileges to administrator, or gain remote code execution, leading to complete server takeover or data loss.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the BM Content Builder plugin to version 3.17.1 or later immediately.</li>
<li>Audit WordPress installations for unauthorized administrative account creation, which often occurs following the deletion of <code>wp-config.php</code>.</li>
<li>Ensure that critical configuration files like <code>wp-config.php</code> have restrictive file system permissions that prevent the web server user from deleting them, where possible.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>wordpress</category></item></channel></rss>