A significant security flaw has been discovered in the Beaver Builder – WordPress Page Builder plugin, affecting all versions up to and including 2.9.4. This vulnerability, identified as CVE-2025-12558, could allow unauthorized access to sensitive information on your WordPress site.
The issue stems from a weakness in the plugin’s `get_attachment_sizes` function. This weakness could allow an authenticated attacker, even with just Contributor-level access, to view private attachment data. This includes details like the file path and other meta-data for attachments that are meant to be private, in draft mode, or password-protected. Essentially, it could allow someone with low-level access to see content they shouldn’t be able to.
CVE Details
- Product: Beaver Builder – WordPress Page Builder
- CVE ID: CVE-2025-12558
- Published Date: December 09, 2025
- Severity: Medium
- Status: Analyzed
Affected Products
All versions of the Beaver Builder – WordPress Page Builder plugin up to, and including, 2.9.4 are affected by this vulnerability.
Current Status
The vulnerability has been analyzed and a fix has been released in version 2.9.4.1 of the Beaver Builder plugin.
Severity Level
This vulnerability is rated as Medium severity. While it requires an authenticated attacker (meaning they need a user account on your WordPress site), the ability to access private information that should be protected is a serious concern for data privacy and security.
Possible Solutions
To protect your WordPress website from this sensitive information exposure vulnerability, it is crucial to update your Beaver Builder – WordPress Page Builder plugin immediately to version 2.9.4.1 or higher. This update includes improved capability checks to ensure that only authorized users can view private attachment data.
If you are using the companion Beaver Builder Themer, ensure it is updated to version 1.5.2.1 as well, as indicated in the changelog for the fix.
References
plugins.trac.wordpress.org/browser/beaver-builder-lite-version/trunk/classes/class-fl-controls.php#L216
plugins.trac.wordpress.org/browser/beaver-builder-lite-version/trunk/classes/class-fl-controls.php#L71
plugins.trac.wordpress.org/changeset/3406987
www.wordfence.com/threat-intel/vulnerabilities/id/eb2f6c67-ef4a-4afc-bd61-6c0185e34a8?source=cve


