Impact
The vulnerability in Beaver Builder Page Builder allows an authenticated user with author-level access or higher to inject arbitrary scripts through the Button Module’s 'button' setting. When the affected page is viewed, the injected code is executed in the browser, leading to potential data theft, phishing, or defacement. This stored XSS flaw results in confidentiality and integrity risks across all users who view the compromised page.
Affected Systems
All WordPress sites that have the Beaver Builder Page Builder – Drag and Drop Website Builder plugin installed with versions up to and including 2.10.2.2. Anyone with a WordPress role that possesses the edit_posts capability, which by default includes Author, Editor, and Administrator roles, could exploit the flaw.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity vulnerability. The exploit requires authenticated access and does not rely on a remote code execution vector, limiting the attack surface to users with edit rights. EPSS is not available, so the observed exploitation probability cannot be quantified. The vulnerability is not listed in CISA KEV, but its nature and moderate CVSS mean that sites with exposed author or editor accounts should treat it as a priority to remediate.
OpenCVE Enrichment