CVE-2025-0859 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1…
Medium CVSS: 6.5

CVE-2025-0859

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.6 via the template_via_url() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Vendor
Boldgrid
Product
Post And Page Builder
CWE
CWE-22
Yayın Tarihi
2025-02-06 10:15:08
Güncelleme
2025-03-19 20:35:32
Source Identifier
security@wordfence.com
KEV Date Added
-

Kategoriler

Referanslar