All 4 CVE vulnerabilities found in BM Content Builder, with AI-generated Chinese analysis, references, and POCs.
Vendor: SeaTheme
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-69055 | WordPress BM Content Builder plugin < 3.16.3.3 - Arbitrary File Download vulnerability CWE-22 | 6.5 | Medium | 2026-01-22 |
| CVE-2025-59002 | WordPress BM Content Builder Plugin < 3.16.3.3 - Arbitrary File Deletion Vulnerability CWE-22 | 7.7 | High | 2025-09-26 |
| CVE-2025-1777 | BM Content Builder <= 3.16.2.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via ux_cb_page_options_save CWE-862 | 6.4 | Medium | 2025-06-06 |
| CVE-2025-1279 | BM Content Builder <= 3.16.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update CWE-862 | 8.8 | High | 2025-04-25 |
All 4 known CVE vulnerabilities affecting BM Content Builder with full Chinese analysis, references, and POCs where available.