Description
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable get_autosuggest_values AJAX endpoint is reachable by any Contributor who owns a draft post, as the required fl_ajax_update nonce is emitted into the block editor for any user who can edit a Beaver Builder post type.
Published: 2026-10-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin is vulnerable to blind SQL injection via the 'fields[][value]' parameter in all versions up to 2.11.0.5. The vulnerability arises from insufficient escaping and lack of prepared statements, allowing authenticated contributors to append additional SQL queries. Exploitation can result in extraction of sensitive database information.

Affected Systems

The affected product is Beaver Builder Page Builder – Drag and Drop Website Builder, version 2.11.0.5 and earlier.

Risk and Exploitability

This vulnerability carries a CVSS score of 6.5 (medium). The EPSS score is not available, and it is not listed in the CISA KEV catalog. An attacker must have at least contributor-level access to a Beaver Builder post, which is required for the vulnerable get_autosuggest_values endpoint. The vulnerability description does not quantify how common contributor-level access is, so the overall risk depends on the site’s user roles. Based on the description, it is inferred that sites with multiple users who can edit Beaver Builder posts are more likely to have an attacker with the necessary access. Because injection is blind, detection requires observing side effects; however, once triggered, an attacker can extract sensitive data from the database.

Generated by OpenCVE AI on October 3, 2026 at 03:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Beaver Builder plugin to 2.11.0.6 or newer, which removes the vulnerable 'fields[][value]' handling.
  • Restrict contributor or editor roles if they are not needed, or remove contributor permissions from users to reduce exposure.
  • If immediate update is not possible, disable the autosuggest endpoint by removing or overriding the 'class-fl-builder-auto-suggest.php' file so that the vulnerable 'fields[][value]' input is not processed.

Generated by OpenCVE AI on October 3, 2026 at 03:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable get_autosuggest_values AJAX endpoint is reachable by any Contributor who owns a draft post, as the required fl_ajax_update nonce is emitted into the block editor for any user who can edit a Beaver Builder post type.
Title Beaver Builder Page Builder <= 2.11.0.5 - Authenticated (Contributor+) SQL Injection via 'fields[][value]' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:47.687Z

Reserved: 2026-09-22T16:59:37.366Z

Link: CVE-2026-95865

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:53.272Z

cve-icon NVD

Status : Received

Published: 2026-10-03T03:16:37.533

Modified: 2026-10-03T16:16:46.470

Link: CVE-2026-95865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T04:00:12Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')