Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-8427 2 The Beaver Builder Team, Wordpress 2 Beaver Builder, Wordpress 2025-10-24 6.4 Medium
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 2.9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-43926 2 Fastlinemedia, The Beaver Builder Team 2 Beaver Builder, Beaver Builder 2025-01-02 7.1 High
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.