{"id":"CVE-2025-12558","details":"The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via the 'get_attachment_sizes' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the path and meta data of private attachments, which can be used to view the attachments.","modified":"2026-03-15T14:13:22.341286Z","published":"2025-12-09T16:17:34.243Z","references":[{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/trunk/classes/class-fl-controls.php#L216"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/trunk/classes/class-fl-controls.php#L71"},{"type":"ADVISORY","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb2f6c67-ef4a-4afc-bd61-6c0185e354a8?source=cve"},{"type":"FIX","url":"https://plugins.trac.wordpress.org/changeset/3406987"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"2.9.4.1"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12558.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}