Medium severity6.5NVD Advisory· Published Feb 6, 2025· Updated Jun 17, 2026
CVE-2025-0859
CVE-2025-0859
Description
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.6 via the template_via_url() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:boldgrid:post_and_page_builder:*:*:*:*:*:wordpress:*:*Range: <1.27.7
- Range: <=1.27.6
- Range: 0
Patches
Vulnerability mechanics
References
5- github.com/BoldGrid/post-and-page-builder/pull/638/commits/10e4d1d96fd2735379049259d15896fa6dd35471nvdPatch
- plugins.trac.wordpress.org/browser/post-and-page-builder/trunk/includes/class-boldgrid-editor-preview.phpnvdPatch
- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/111a1e7f-bc87-4130-a0b2-422d0f98afb6nvdThird Party Advisory
- wordpress.org/plugins/post-and-page-builder/nvdProduct
News mentions
0No linked articles in our index yet.