🔐 CVE Alert

CVE-2025-0859

MEDIUM 6.5

Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.6 via the template_via_url() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CWE CWE-22
Vendor boldgrid
Product post and page builder by boldgrid – visual drag and drop editor
Published Feb 6, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for boldgrid post and page builder by boldgrid – visual drag and drop editor

Be the first to know when new medium vulnerabilities affecting boldgrid post and page builder by boldgrid – visual drag and drop editor are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

boldgrid / Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
0 ≤ 1.27.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/111a1e7f-bc87-4130-a0b2-422d0f98afb6?source=cve wordpress.org: https://wordpress.org/plugins/post-and-page-builder/#developers plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/post-and-page-builder/trunk/includes/class-boldgrid-editor-preview.php#L178 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?old=3234175&old_path=post-and-page-builder%2Ftags%2F1.27.7%2Fincludes%2Fclass-boldgrid-editor-preview.php&new=3234175&new_path=post-and-page-builder%2Ftags%2F1.27.7%2Fincludes%2Fclass-boldgrid-editor-preview.php github.com: https://github.com/BoldGrid/post-and-page-builder/pull/638/commits/10e4d1d96fd2735379049259d15896fa6dd35471

Credits

Michael Mazzolini