
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12782 is an authorization bypass vulnerability in the Beaver Builder – WordPress Page Builder plugin (Lite version) for WordPress, affecting all versions up to and including 2.9.4. The flaw allows authenticated attackers with contributor-level access or higher to disable the Beaver Builder layout on arbitrary posts and pages, causing content integrity issues and layout disruption. It was published on December 4, 2025, and assigned a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE, Wordfence).
The vulnerability is classified as CWE-862 (Missing Authorization) and stems from the plugin's disable() function failing to properly verify whether the requesting user has the necessary permissions to modify a given post or page (Wordfence). An authenticated attacker with at least contributor-level access can send a crafted network request to invoke the disable() function against arbitrary post or page IDs, bypassing ownership or capability checks. No user interaction is required, and the attack complexity is low, making it straightforward to exploit once authenticated (Red Hat CVE).
Successful exploitation allows an authenticated contributor (or higher-privileged user) to strip the Beaver Builder layout from any post or page on the WordPress site, resulting in content integrity loss and visual disruption for site visitors. The vulnerability has no confidentiality or availability impact — it is limited to a low integrity impact — but could be used to deface or disrupt the presentation of targeted pages across an entire WordPress installation (Red Hat CVE, Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-12782. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid account with at least contributor-level access, limiting the attacker pool to authenticated users.
/wp-json/wp/v2/posts or /wp-json/wp/v2/pages) to identify targets whose layouts should be disrupted.disable() function with the target post/page ID, bypassing the missing authorization check.wp-admin/admin-ajax.php with Beaver Builder-related action parameters (e.g., fl_builder_disable) targeting post/page IDs not owned by the requesting user._fl_builder_enabled) from posts or pages not edited by the legitimate author.Users should update the Beaver Builder – WordPress Page Builder (Lite) plugin to version 2.9.4.1 or later, which includes the patch addressing the missing authorization check in the disable() function (WordPress Trac). No configuration-based workaround is available; upgrading is the only recommended remediation. Site administrators should also audit contributor-level accounts and restrict plugin access to trusted users as a defense-in-depth measure.
Sucuri noted CVE-2025-12782 in their December 2025 vulnerability patch roundup, highlighting it as part of a broader set of WordPress plugin issues requiring attention (Sucuri Blog). The vulnerability was assigned and disclosed by Wordfence, which maintains a threat intelligence entry for it. General community reaction has been muted given the medium severity and limited exploitation potential.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."