WordPress security by component
Beaver Builder – WordPress Page Builder
Plugin description
Beaver Builder – WordPress Page Builder provides a visual drag-and-drop editor for creating and arranging WordPress page content and website layouts.
Beaver Builder – WordPress Page Builder (beaver-builder-lite-version) is a WordPress plugin with 21 published CVE records in this archive. The latest tracked vulnerability was published Sep 08, 2026; the highest published CVSS base score is 8.5.
Plugin slug:
beaver-builder-lite-versionLatest vulnerability
CVE-2026-18021: Beaver Builder permits unauthenticated shortcode execution
Beaver Builder through 2.10.3.1 allows unauthenticated callers to reach an action that passes an inadequately validated value to do_shortcode. An attacker can execute shortcodes registered on the site; the information exposed or changes made depend on the installed shortcode handlers.
| Safe version |
|
||
|---|---|---|---|
| Sep 08, 2026 |
CVE-2026-18021
Beaver Builder permits unauthenticated shortcode execution
Beaver Builder through 2.10.3.1 allows unauthenticated callers to reach an action that passes an inadequately validated value to do_shortcode. An attacker can execute shortcodes registered on the site; the information exposed or changes made depend on the installed shortcode handlers.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 15, 2026 |
CVE-2026-17090
Beaver Builder button code permits Author stored XSS
Beaver Builder through 2.10.2.2 exposes its editor by default to roles carrying edit_posts, including Authors. The Button module's button code setting is stored and rendered without adequate sanitization and escaping, allowing an Author to persist script that executes for visitors to the page. The public.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 15, 2026 |
CVE-2026-40744
Beaver Builder: SQL injection
Beaver Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.10.1.2.
|
2.10.1.5 |
CVE8.5
NVDPending
|
| Feb 11, 2026 |
CVE-2026-1231
Beaver Builder Page Builder – Drag and Drop Website Builder: Cross-site scripting
Beaver Builder Page Builder – Drag and Drop Website Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jan 22, 2026 |
CVE-2025-69319
Beaver Builder: Code execution
Beaver Builder is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Dec 23, 2025 |
CVE-2025-12934
Beaver Builder – WordPress Page Builder: A security weakness
Beaver Builder – WordPress Page Builder is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Dec 09, 2025 |
CVE-2025-12558
Beaver Builder – WordPress Page Builder: Sensitive information exposure
Beaver Builder – WordPress Page Builder is affected by sensitive information exposure. Exploitation requires an authenticated contributor account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Dec 02, 2025 |
CVE-2025-11726
Beaver Builder – WordPress Page Builder: A security weakness
Beaver Builder – WordPress Page Builder is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 29, 2024 |
CVE-2024-9505
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Aug 29, 2024 |
CVE-2024-43926
Beaver Builder: Cross-site scripting
Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Aug 29, 2024 |
CVE-2024-7895
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jul 21, 2024 |
CVE-2024-37500
Beaver Builder: Cross-site scripting
Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| May 14, 2024 |
CVE-2024-3923
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 02, 2024 |
CVE-2024-2925
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 29, 2024 |
CVE-2024-30425
Beaver Builder: Cross-site scripting
Beaver Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1080
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1074
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1038
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD6.1
|
| Mar 13, 2024 |
CVE-2024-0896
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Dec 29, 2023 |
CVE-2023-50889
Beaver Builder – WordPress Page Builder: Cross-site scripting
Beaver Builder – WordPress Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Sep 06, 2022 |
CVE-2022-36425
Beaver Builder Lite Version: Broken access control
Beaver Builder Lite Version is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE5.4
NVD9.8
|