← WordPress Vulnerabilities
WordPress security by component

Beaver Builder – WordPress Page Builder

Beaver Builder – WordPress Page Builder provides a visual drag-and-drop editor for creating and arranging WordPress page content and website layouts.

Beaver Builder – WordPress Page Builder (beaver-builder-lite-version) is a WordPress plugin with 21 published CVE records in this archive. The latest tracked vulnerability was published Sep 08, 2026; the highest published CVSS base score is 8.5.

Plugin slug: beaver-builder-lite-version

CVE-2026-18021: Beaver Builder permits unauthenticated shortcode execution

Beaver Builder through 2.10.3.1 allows unauthenticated callers to reach an action that passes an inadequately validated value to do_shortcode. An attacker can execute shortcodes registered on the site; the information exposed or changes made depend on the installed shortcode handlers.

PublishedSep 08, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for beaver-builder-lite-version
Safe version
Sep 08, 2026 CVE-2026-18021
Beaver Builder permits unauthenticated shortcode execution
Beaver Builder through 2.10.3.1 allows unauthenticated callers to reach an action that passes an inadequately validated value to do_shortcode. An attacker can execute shortcodes registered on the site; the information exposed or changes made depend on the installed shortcode handlers.
See mitigation notes
CVE6.5
NVDPending
Aug 15, 2026 CVE-2026-17090
Beaver Builder button code permits Author stored XSS
Beaver Builder through 2.10.2.2 exposes its editor by default to roles carrying edit_posts, including Authors. The Button module's button code setting is stored and rendered without adequate sanitization and escaping, allowing an Author to persist script that executes for visitors to the page. The public.
See mitigation notes
CVE6.4
NVDPending
Apr 15, 2026 CVE-2026-40744
Beaver Builder: SQL injection
Beaver Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.10.1.2.
2.10.1.5
CVE8.5
NVDPending
Feb 11, 2026 CVE-2026-1231
Beaver Builder Page Builder – Drag and Drop Website Builder: Cross-site scripting
Beaver Builder Page Builder – Drag and Drop Website Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Jan 22, 2026 CVE-2025-69319
Beaver Builder: Code execution
Beaver Builder is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVDPending
Dec 23, 2025 CVE-2025-12934
Beaver Builder – WordPress Page Builder: A security weakness
Beaver Builder – WordPress Page Builder is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.1
NVDPending
Dec 09, 2025 CVE-2025-12558
Beaver Builder – WordPress Page Builder: Sensitive information exposure
Beaver Builder – WordPress Page Builder is affected by sensitive information exposure. Exploitation requires an authenticated contributor account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD4.3
Dec 02, 2025 CVE-2025-11726
Beaver Builder – WordPress Page Builder: A security weakness
Beaver Builder – WordPress Page Builder is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Oct 29, 2024 CVE-2024-9505
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 29, 2024 CVE-2024-43926
Beaver Builder: Cross-site scripting
Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Aug 29, 2024 CVE-2024-7895
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jul 21, 2024 CVE-2024-37500
Beaver Builder: Cross-site scripting
Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
May 14, 2024 CVE-2024-3923
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 02, 2024 CVE-2024-2925
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 29, 2024 CVE-2024-30425
Beaver Builder: Cross-site scripting
Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 13, 2024 CVE-2024-1080
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1074
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1038
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD6.1
Mar 13, 2024 CVE-2024-0896
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 29, 2023 CVE-2023-50889
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Sep 06, 2022 CVE-2022-36425
Beaver Builder Lite Version: Broken access control
Beaver Builder Lite Version is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE5.4
NVD9.8