CVE-2025-12558

Source
https://cve.org/CVERecord?id=CVE-2025-12558
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12558.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-12558
Published
2025-12-09T16:17:34.243Z
Modified
2026-03-15T14:13:22.341286Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via the 'getattachmentsizes' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the path and meta data of private attachments, which can be used to view the attachments.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "2.9.4.1"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12558.json"