{"id":"CVE-2025-12558","title":"The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via the 'get_attachment_sizes' function","summary":"The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via the 'get_attachment_sizes' function. This makes it possible for authenticate…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"vendor":"fastlinemedia","product":"beaver_builder","affected":["beaver_builder < 2.9.4.1"],"patched":["beaver_builder 2.9.4.1"],"published":"2025-12-09","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-12558","references":[{"url":"https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/trunk/classes/class-fl-controls.php#L216","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/trunk/classes/class-fl-controls.php#L71","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3406987","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb2f6c67-ef4a-4afc-bd61-6c0185e354a8?source=cve","label":"security@wordfence.com"}],"tags":["nvd"],"epss":0.00407,"epssPercentile":0.32728,"ingestedAt":"2026-10-07T20:46:46.783Z","slug":"CVE-2025-12558","body":"## Overview\n\nThe Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via the 'get_attachment_sizes' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the path and meta data of private attachments, which can be used to view the attachments.\n\n## Affected\n\n- `beaver_builder < 2.9.4.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `beaver_builder 2.9.4.1`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}