← WordPress Vulnerabilities
WordPress security by component

BM Content Builder

BM Content Builder is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 06, 2025; the highest published CVSS base score is 8.8.

Plugin slug: bm-content-builder

CVE-2025-1777: BM Content Builder: A security weakness

BM Content Builder is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedJun 06, 2025
Safe version guidanceSee mitigation notes
Published vulnerabilities for bm-content-builder
Safe version
Jun 06, 2025 CVE-2025-1777
BM Content Builder: A security weakness
BM Content Builder is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.4
NVDPending
Apr 25, 2025 CVE-2025-1279
BM Content Builder: Privilege escalation or authentication bypass
BM Content Builder is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending