← Back to search

CVE-2025-1281

8.8 HIGH

Published 2026-09-22 · Updated 2026-09-22

AI risk analysis

Summary
The flaw allows authenticated attackers with Subscriber-level access or higher to delete arbitrary files, potentially leading to remote code execution.
Exploitability
Exploitation is relatively straightforward for attackers with Subscriber-level access or higher, as no specific technical skills are required beyond file path manipulation.
Blast radius
If exploited, the impact could be severe, as it may lead to full server compromise and remote code execution.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 3.17.1 or later of the BM Content Builder plugin.
rcewebwp-plugin

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding, 3.17.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.