
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12934 is a Missing Authorization vulnerability in the Beaver Builder – WordPress Page Builder plugin that allows authenticated attackers with Subscriber-level access or higher to perform unauthorized access and modification of WordPress post data. The flaw affects all versions up to and including 2.9.4.1 of the plugin. It was published on December 23, 2025, with the advisory assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Red Hat CVE).
The root cause is a missing capability check (CWE-862) on the duplicate_wpml_layout function within class-fl-builder-model.php. Because no authorization check validates whether the requesting user has sufficient privileges, any authenticated user — including those with the lowest default WordPress role (Subscriber) — can invoke this function over the network without user interaction. The function allows the caller to overwrite the content of arbitrary posts with content from other existing posts, including private or password-protected ones, and can effectively destroy content not preserved in revisions or backups. The vulnerable code paths are visible in the plugin's public Trac repository (WordPress Trac, WordPress Changeset).
Successful exploitation enables an authenticated attacker to read private or password-protected post content (high confidentiality impact) and overwrite or effectively delete arbitrary post content that was created with Beaver Builder (high integrity impact). Content not saved in revisions or backups may be permanently lost. Availability is not directly impacted by the vulnerability itself, but irreversible content destruction represents a significant operational risk for affected WordPress sites (Wordfence, ENISA EUVD).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Wordfence). The EPSS score is approximately 0.028%, reflecting a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA referenced it in its weekly vulnerability bulletin for the week of December 22, 2025 (CISA Bulletin). Exploitation requires only a valid WordPress account at Subscriber level or above, lowering the barrier for any registered user on a targeted site.
/wp-content/plugins/beaver-builder-lite-version/readme.txt) or using tools like WPScan.duplicate_wpml_layout function with a crafted payload specifying the source post ID (private/protected content to expose) and the destination post ID (post to overwrite), bypassing the missing capability check.duplicate_wpml_layout from low-privilege user accounts; repeated requests targeting multiple post IDs in rapid succession.The primary remediation is to update the Beaver Builder – WordPress Page Builder plugin to a version beyond 2.9.4.1, which includes the fix for the missing capability check (patch available via the WordPress plugin repository changeset 3425646) (WordPress Changeset). If an immediate update is not possible, site administrators should consider temporarily disabling the plugin, restricting user registration to prevent new Subscriber-level accounts, and reviewing existing low-privilege accounts for suspicious activity. Regular content backups should be maintained to enable recovery in the event of content destruction (Wordfence).
Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026 (Wordfence Blog). Sucuri also referenced the issue in their December 2025 vulnerability patch roundup (Sucuri Blog). Social media accounts including TheHackerWire and RedPacketSecurity shared the disclosure across Mastodon and Bluesky, generating moderate community awareness. CISA included the vulnerability in its weekly bulletin for the week of December 22, 2025 (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."