Impact
The Beaver Builder Plugin is vulnerable to a reflected Cross‑Site Scripting flaw caused by insufficient input sanitization and output escaping of the no_results_message node_preview parameter. Attackers may inject arbitrary scripts that execute when a user follows a crafted link. The flaw is unauthenticated and does not require any privileged access, but it can compromise client‑side security.
Affected Systems
The flaw exists in the Beaver Builder Plugin (Starter Version) from The Beaver Builder Team. All releases up to and including version 2.11.0.1 are affected; newer releases are not known to be vulnerable.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. No EPSS score is published, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that a victim click a crafted link; no server‑side authentication is needed. The attack path is straightforward for an attacker who can lure a user to the malicious URL.
OpenCVE Enrichment