CVE-2025-12934
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12934 is a Missing Authorization vulnerability in the Beaver Builder – WordPress Page Builder plugin that allows authenticated attackers with Subscriber-level access or higher to perform unauthorized access and modification of WordPress post data. The flaw affects all versions up to and including 2.9.4.1 of the plugin. It was published on December 23, 2025, with the advisory assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is a missing capability check (CWE-862) on the duplicate_wpml_layout function within class-fl-builder-model.php. Because no authorization check validates whether the requesting user has sufficient privileges, any authenticated user — including those with the lowest default WordPress role (Subscriber) — can invoke this function over the network without user interaction. The function allows the caller to overwrite the content of arbitrary posts with content from other existing posts, including private or password-protected ones, and can effectively destroy content not preserved in revisions or backups. The vulnerable code paths are visible in the plugin's public Trac repository (WordPress Trac, WordPress Changeset).

Impact

Successful exploitation enables an authenticated attacker to read private or password-protected post content (high confidentiality impact) and overwrite or effectively delete arbitrary post content that was created with Beaver Builder (high integrity impact). Content not saved in revisions or backups may be permanently lost. Availability is not directly impacted by the vulnerability itself, but irreversible content destruction represents a significant operational risk for affected WordPress sites (Wordfence, ENISA EUVD).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Wordfence). The EPSS score is approximately 0.028%, reflecting a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA referenced it in its weekly vulnerability bulletin for the week of December 22, 2025 (CISA Bulletin). Exploitation requires only a valid WordPress account at Subscriber level or above, lowering the barrier for any registered user on a targeted site.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Beaver Builder plugin version ≤ 2.9.4.1 by checking publicly visible plugin metadata (e.g., /wp-content/plugins/beaver-builder-lite-version/readme.txt) or using tools like WPScan.
  2. Obtain authenticated access: Register or obtain a low-privilege WordPress account (Subscriber level or above) on the target site.
  3. Identify target posts: Enumerate post IDs of private or password-protected posts created with Beaver Builder (e.g., by probing REST API endpoints or observing post ID sequences).
  4. Invoke the vulnerable function: Send an authenticated HTTP request that triggers the duplicate_wpml_layout function with a crafted payload specifying the source post ID (private/protected content to expose) and the destination post ID (post to overwrite), bypassing the missing capability check.
  5. Exfiltrate or destroy content: Read the now-overwritten destination post to access the copied private content, or use the function to overwrite valuable posts with arbitrary content, effectively destroying data not preserved in backups (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to admin-ajax.php or REST API endpoints invoking duplicate_wpml_layout from low-privilege user accounts; repeated requests targeting multiple post IDs in rapid succession.
  • File System: Unexpected changes to post content in the WordPress database for posts built with Beaver Builder, particularly private or password-protected posts showing modified content timestamps.
  • Application Behavior: Private or password-protected posts suddenly accessible or displaying content from other posts; posts with missing or replaced content not attributable to legitimate editorial activity.
  • User Activity: Subscriber-level accounts performing post modification actions that would normally require Editor or Administrator privileges, visible in WordPress activity logs if a logging plugin is installed.

Mitigation and workarounds

The primary remediation is to update the Beaver Builder – WordPress Page Builder plugin to a version beyond 2.9.4.1, which includes the fix for the missing capability check (patch available via the WordPress plugin repository changeset 3425646) (WordPress Changeset). If an immediate update is not possible, site administrators should consider temporarily disabling the plugin, restricting user registration to prevent new Subscriber-level accounts, and reviewing existing low-privilege accounts for suspicious activity. Regular content backups should be maintained to enable recovery in the event of content destruction (Wordfence).

Community reactions

Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026 (Wordfence Blog). Sucuri also referenced the issue in their December 2025 vulnerability patch roundup (Sucuri Blog). Social media accounts including TheHackerWire and RedPacketSecurity shared the disclosure across Mastodon and Bluesky, generating moderate community awareness. CISA included the vulnerability in its weekly bulletin for the week of December 22, 2025 (CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management