Impact
The Beaver Builder Page Builder plugin contains a flaw that causes it to pass user‑controlled content directly to WordPress’s do_shortcode function without validation. This allows anyone without authentication to inject and execute any shortcode within the context of the plugin, which can lead to arbitrary code execution or other undesirable behavior. The weakness is categorized as CWE-94.
Affected Systems
All releases of Beaver Builder – Drag and Drop Website Builder up to and including version 2.11.0.5 are affected. The vulnerability becomes active when a site hosts a Beaver Builder page that contains a Sidebar module populated with a widget that outputs attacker‑controlled text, such as the core Recent Comments widget when comment moderation is disabled or the attacker’s comment is approved.
Risk and Exploitability
The CVSS score of 9.1 classifies this vulnerability as critical. While no EPSS score is published, the lack of authentication and the immediacy of the code‑path make exploitation highly actionable. The vulnerability is not yet listed in the CISA KEV catalog, nevertheless its severity indicates it should be addressed with priority.
OpenCVE Enrichment