Impact
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to and including 2.10.3.1 because it allows user-supplied input to be passed directly to the WordPress do_shortcode function without proper validation. This code‑generation flaw (CWE-94) lets unauthenticated attackers inject any shortcode, which can trigger server‑side code or privileged actions, potentially enabling full compromise of the site if the malicious shortcode performs administrative or file‑manipulation functions.
Affected Systems
WordPress sites that have installed Beaver Builder Page Builder – Drag and Drop Website Builder before version 2.10.3.2 are affected, as those instances lack input validation for do_shortcode; versions 2.10.3.2 and newer contain the fix.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity and the lack of EPSS data or KEV listing suggests limited publicly known exploitation; however, the flaw permits unauthenticated attackers to submit arbitrary shortcodes through the public web interface, potentially leading to execution of server‑side code or privileged actions, which constitutes a significant risk for vulnerable WordPress sites.
OpenCVE Enrichment