Beaver Builder Sensitive Information Exposure Vulnerability (CVE-2025-12558) — Medium Severity

A significant security flaw has been discovered in the Beaver Builder – WordPress Page Builder plugin, affecting all versions up to and including 2.9.4. This vulnerability, identified as CVE-2025-12558, could allow unauthorized access to sensitive information on your WordPress site.

The issue stems from a weakness in the plugin’s `get_attachment_sizes` function. This weakness could allow an authenticated attacker, even with just Contributor-level access, to view private attachment data. This includes details like the file path and other meta-data for attachments that are meant to be private, in draft mode, or password-protected. Essentially, it could allow someone with low-level access to see content they shouldn’t be able to.

CVE Details

  • Product: Beaver Builder – WordPress Page Builder
  • CVE ID: CVE-2025-12558
  • Published Date: December 09, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

All versions of the Beaver Builder – WordPress Page Builder plugin up to, and including, 2.9.4 are affected by this vulnerability.

Current Status

The vulnerability has been analyzed and a fix has been released in version 2.9.4.1 of the Beaver Builder plugin.

Severity Level

This vulnerability is rated as Medium severity. While it requires an authenticated attacker (meaning they need a user account on your WordPress site), the ability to access private information that should be protected is a serious concern for data privacy and security.

Possible Solutions

To protect your WordPress website from this sensitive information exposure vulnerability, it is crucial to update your Beaver Builder – WordPress Page Builder plugin immediately to version 2.9.4.1 or higher. This update includes improved capability checks to ensure that only authorized users can view private attachment data.

If you are using the companion Beaver Builder Themer, ensure it is updated to version 1.5.2.1 as well, as indicated in the changelog for the fix.

References

plugins.trac.wordpress.org/browser/beaver-builder-lite-version/trunk/classes/class-fl-controls.php#L216
plugins.trac.wordpress.org/browser/beaver-builder-lite-version/trunk/classes/class-fl-controls.php#L71
plugins.trac.wordpress.org/changeset/3406987
www.wordfence.com/threat-intel/vulnerabilities/id/eb2f6c67-ef4a-4afc-bd61-6c0185e34a8?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.