Description
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.9.4. This is due to insufficient capability checks in the REST API endpoints under the 'fl-controls/v1' namespace that control site-wide Global Presets. This makes it possible for authenticated attackers with contributor-level access and above to add, modify, or delete global color and background presets that affect all Beaver Builder content site-wide.
Published: 2025-12-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Global preset modification without proper authorization
Action: Update plugin
AI Analysis

Impact

The Beaver Builder – WordPress Page Builder plugin is vulnerable due to missing authorization checks in all REST API endpoints under the 'fl-controls/v1' namespace that manage site‑wide Global Presets. Authenticated attackers with contributor-level access or higher can add, modify, or delete global color and background presets that affect every Beaver Builder page on the site. Designers and site owners could therefore alter the appearance of the entire website without proper approval, impacting brand consistency and potentially breaking the visual design. The flaw is a classic example of Missing Authorization, CWE‑862.

Affected Systems

The vulnerability affects the Beaver Builder Page Builder – Drag and Drop Website Builder plugin (lite) on WordPress. All released versions up to and including 2.9.4 are impacted; newer versions are presumed to contain the fix. The issue manifests when the plugin's REST API is exposed and users with contributor or higher roles are authenticated.

Risk and Exploitability

The CVSS base score of 4.3 reflects a low hazard level, and the EPSS score of less than 1 % indicates a very low likelihood of exploitation at any given time. The flaw is not listed in the CISA KEV catalog. While the attack requires valid user credentials with at least contributor privileges, an attacker who gains such access can modify or delete global presets, potentially compromising the site's design integrity. The attack vector is a REST API call, and the vulnerability hinges on insufficient capability checks.

Generated by OpenCVE AI on April 21, 2026 at 01:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Beaver Builder to the latest version (≥2.9.5) to apply the vendor fix.
  • If an upgrade is not immediately feasible, restrict contributor‑level users from accessing the REST API namespace 'fl-controls/v1' or remove the capability that allows them to edit global presets, enforcing proper access control.
  • Monitor WordPress REST API logs for unexpected calls to the 'fl-controls/v1' endpoints and remediate promptly.

Generated by OpenCVE AI on April 21, 2026 at 01:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 11 Dec 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Fastlinemedia
Fastlinemedia beaver Builder
CPEs cpe:2.3:a:fastlinemedia:beaver_builder:*:*:*:*:lite:wordpress:*:*
Vendors & Products Fastlinemedia
Fastlinemedia beaver Builder

Thu, 04 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpbeaverbuilder
Wpbeaverbuilder beaver Builder
Vendors & Products Wordpress
Wordpress wordpress
Wpbeaverbuilder
Wpbeaverbuilder beaver Builder

Tue, 02 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.9.4. This is due to insufficient capability checks in the REST API endpoints under the 'fl-controls/v1' namespace that control site-wide Global Presets. This makes it possible for authenticated attackers with contributor-level access and above to add, modify, or delete global color and background presets that affect all Beaver Builder content site-wide.
Title Beaver Builder – WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Global Preset Modification
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Fastlinemedia Beaver Builder
Wordpress Wordpress
Wpbeaverbuilder Beaver Builder
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:17:41.566Z

Reserved: 2025-10-13T21:41:33.879Z

Link: CVE-2025-11726

cve-icon Vulnrichment

Updated: 2025-12-02T13:57:44.627Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-02T08:15:51.343

Modified: 2025-12-11T20:27:36.110

Link: CVE-2025-11726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T01:15:20Z

Weaknesses