SeaTheme BM Content Builder Path Traversal Vulnerability Allowing Arbitrary File Deletion
Vulnerability
A path traversal vulnerability has been identified in the SeaTheme BM Content Builder WordPress plugin, versions prior to 3.16.3.3. This vulnerability allows for improper limitation of a pathname to a restricted directory, potentially leading to arbitrary file deletion. Exploitation of this issue could result in the deletion of critical files from a website, causing the site to malfunction or break.
Impact
Exploitation of this vulnerability could allow a malicious actor to delete files from the affected WordPress site. If core files are removed, it could disrupt the site's functionality and cause it to stop working properly.
Remediation
Users of the SeaTheme BM Content Builder WordPress plugin should update to version 3.16.3.3 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
