← WordPress Vulnerabilities
WordPress security by component

Beaver Builder

Beaver Builder is a WordPress component with 19 published CVE records in this archive. The latest tracked vulnerability was published Apr 15, 2026; the highest CVE/CNA score is 8.5.

Plugin slug: beaver-builder-lite-version

CVE-2026-40744: Beaver Builder: SQL injection

Beaver Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.10.1.2.

PublishedApr 15, 2026
Known safe version2.10.1.5
Safe version
Apr 15, 2026 CVE-2026-40744
Beaver Builder: SQL injection
Beaver Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.10.1.2.
2.10.1.5
CVE8.5
NVDPending
Feb 11, 2026 CVE-2026-1231
Beaver Builder Page Builder – Drag and Drop Website Builder: Cross-site scripting
Beaver Builder Page Builder – Drag and Drop Website Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Jan 22, 2026 CVE-2025-69319
Beaver Builder: Code execution
Beaver Builder is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVDPending
Dec 23, 2025 CVE-2025-12934
Beaver Builder – WordPress Page Builder: A security weakness
Beaver Builder – WordPress Page Builder is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.1
NVDPending
Dec 09, 2025 CVE-2025-12558
Beaver Builder – WordPress Page Builder: Sensitive information exposure
Beaver Builder – WordPress Page Builder is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD4.3
Dec 02, 2025 CVE-2025-11726
Beaver Builder – WordPress Page Builder: A security weakness
Beaver Builder – WordPress Page Builder is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Oct 29, 2024 CVE-2024-9505
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 29, 2024 CVE-2024-43926
Beaver Builder: Cross-site scripting
Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Aug 29, 2024 CVE-2024-7895
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jul 21, 2024 CVE-2024-37500
Beaver Builder: Cross-site scripting
Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
May 14, 2024 CVE-2024-3923
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 02, 2024 CVE-2024-2925
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 29, 2024 CVE-2024-30425
Beaver Builder: Cross-site scripting
Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 13, 2024 CVE-2024-1080
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1074
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1038
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD6.1
Mar 13, 2024 CVE-2024-0896
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 29, 2023 CVE-2023-50889
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Sep 06, 2022 CVE-2022-36425
Beaver Builder Lite Version: A security weakness
Beaver Builder Lite Version is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD9.8