Sceawere
Vulnerability Detail
CVE-2026-92084UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Beaver Builder Arbitrary Shortcode Execution
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 2h ago
- Vendor
- beaverbuilder
- Product
- Beaver Builder Page Builder – Drag and Drop Website Builder
- Attack Type
- CWE-94 Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-10-03T08:16:26.990Z",
"pubdate": "2026-10-03T08:16:26.990Z",
"executiveSummary": "The Beaver Builder Page Builder plugin for WordPress is susceptible to an arbitrary shortcode execution vulnerability across all versions up to and including 2.11.0.5.\nThis security flaw is categorized as an improper input validation vulnerability where user-supplied data is passed to the do_shortcode function without sufficient sanitization or verification.\nThe vulnerability allows unauthenticated attackers to leverage existing page components to execute arbitrary shortcodes on the target server.\nThe primary risk implication is the potential for unauthorized execution of server-side logic, which could lead to sensitive data exposure, cross-site scripting (XSS), or other destructive actions depending on the available shortcodes on the WordPress installation.\nSuccessful exploitation requires the target site to possess a Beaver Builder page containing a Sidebar module configured to display dynamic or user-controlled text, such as the WordPress 'Recent Comments' widget.\nBecause the vulnerability can be triggered without prior authentication, it poses a significant threat to sites that allow public interaction, such as comments or user-generated content, if those inputs are reflected within a widget controlled by the Beaver Builder plugin.",
"technicalDetails": "The vulnerability resides within the Beaver Builder Page Builder’s handling of shortcode rendering in the Sidebar module. The root cause is the failure to properly validate or sanitize input values before they are processed by the WordPress do_shortcode function.\nIn WordPress architecture, do_shortcode is a powerful function designed to parse content for shortcode tags and execute the associated callback functions. When an application passes unvalidated user-controlled content into this function, it effectively grants an attacker the ability to trigger any registered shortcode within the system.\nThe attack flow begins with the attacker identifying a Beaver Builder page utilizing the Sidebar module. This module must be configured to output content that can be influenced by the attacker, such as the core WordPress Recent Comments widget. If comment moderation is disabled, or if the attacker has an approved comment, they can inject malicious shortcode sequences into the comment body or author name fields.\nWhen the Beaver Builder Sidebar module renders the widget, it retrieves the stored, malicious string. Because the plugin logic subsequently passes this string to do_shortcode without adequate mediation, the server executes the injected shortcode.\nThis exploitation vector does not require administrative privileges or session-based authentication, making it a remote, unauthenticated vulnerability. The impact of such exploitation is highly dependent on the shortcodes available in the environment; an attacker might utilize common shortcodes to manipulate site content, exfiltrate data from the database, or conduct secondary attacks like Stored Cross-Site Scripting (XSS) if the rendered shortcode output includes unsanitized HTML or JavaScript.\nThe vulnerability persists across all versions up to and including 2.11.0.5. By leveraging legitimate site functionality to bypass input filters, an attacker can reliably trigger execution within the WordPress application context, bypassing standard security barriers that would otherwise prevent unauthenticated users from executing server-side logic."
}