Description
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved.
Published: 2026-10-03
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Arbitrary Shortcode Execution
Action: Immediate Patch
AI Analysis

Impact

The Beaver Builder Page Builder plugin contains a flaw that causes it to pass user‑controlled content directly to WordPress’s do_shortcode function without validation. This allows anyone without authentication to inject and execute any shortcode within the context of the plugin, which can lead to arbitrary code execution or other undesirable behavior. The weakness is categorized as CWE-94.

Affected Systems

All releases of Beaver Builder – Drag and Drop Website Builder up to and including version 2.11.0.5 are affected. The vulnerability becomes active when a site hosts a Beaver Builder page that contains a Sidebar module populated with a widget that outputs attacker‑controlled text, such as the core Recent Comments widget when comment moderation is disabled or the attacker’s comment is approved.

Risk and Exploitability

The CVSS score of 9.1 classifies this vulnerability as critical. While no EPSS score is published, the lack of authentication and the immediacy of the code‑path make exploitation highly actionable. The vulnerability is not yet listed in the CISA KEV catalog, nevertheless its severity indicates it should be addressed with priority.

Generated by OpenCVE AI on October 3, 2026 at 09:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Beaver Builder to the latest available version, which includes the fix for the insecure shortcode handling.
  • Remove or disable sidebar widgets that allow raw text input, such as the Recent Comments widget, so that attacker‑controlled content is not supplied.
  • Configure a WordPress security plugin or firewall to block or sanitize shortcodes that appear within page builder widgets.

Generated by OpenCVE AI on October 3, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved.
Title Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:14:04.869Z

Reserved: 2026-09-15T13:13:39.819Z

Link: CVE-2026-92084

cve-icon Vulnrichment

Updated: 2026-10-03T15:14:00.516Z

cve-icon NVD

Status : Received

Published: 2026-10-03T08:16:26.990

Modified: 2026-10-03T16:16:41.610

Link: CVE-2026-92084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T10:00:14Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')