A significant security flaw has been identified in the “Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents” plugin for WordPress. This vulnerability, tracked as CVE-2025-12189, is a type of Cross-Site Request Forgery (CSRF) that affects all plugin versions up to and including 7.10.1321. Essentially, it means that an attacker could trick a website administrator into unknowingly uploading malicious files, potentially allowing them to take full control of the website.
CVE Details
- Product: Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress
- Published Date: December 5, 2025
- Severity: Medium
- Status: Analyzed
Affected Products
The Cross-Site Request Forgery vulnerability impacts all versions of the Bread & Butter plugin for WordPress up to, and including, version 7.10.1321. This means if you are running any version within this range, your website could be at risk.
Current Status
This vulnerability has been formally analyzed and documented. While the technical details are understood, it is crucial for administrators to take action to protect their WordPress installations.
Severity Level
Rated as Medium severity, this vulnerability should not be overlooked. While an attacker needs to trick an administrator into clicking a malicious link, the potential impact is severe. Successful exploitation could lead to arbitrary file uploads, allowing the attacker to execute code remotely (Remote Code Execution or RCE) on your server. This could compromise your website, leading to data theft, defacement, or further attacks on your network.
Possible Solutions
To safeguard your WordPress website from CVE-2025-12189, it is highly recommended to take the following steps:
- Update Immediately: Check for and apply any available updates for the “Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents” plugin. Developers typically release patches quickly once vulnerabilities are disclosed. Ensure you update to a version beyond 7.10.1321.
- Educate Administrators: Train your website administrators and users to be wary of suspicious links or unsolicited emails. A key component of this attack relies on social engineering to trick a logged-in admin into performing an unintended action.
- Web Application Firewall (WAF): Employ a robust Web Application Firewall. A WAF can help detect and block malicious requests, adding an extra layer of defense against CSRF and arbitrary file upload attempts.
- Regular Backups: Maintain regular backups of your WordPress site. In the unfortunate event of a compromise, a recent backup can significantly reduce downtime and data loss.
For more general guidance on keeping your WordPress site secure, you might find our articles on General WordPress Security Tips and Understanding Cross-Site Request Forgery (CSRF) helpful.
References
https://github.com/d0n601/CVE-2025-12189
https://plugins.trac.wordpress.org/browser/bread-butter/trunk/src/Base/Ajax.php#L411
https://ryankozak.com/posts/cve-2025-12189/
https://www.wordfence.com/threat-intel/vulnerabilities/id/bb280004-e0ba-44c8-a205-8fec30900d86?source=cve
https://github.com/d0n601/CVE-2025-12189


