Junglewise Threat Intelligence

CVE-2026-18021: Beaver Builder arbitrary shortcode execution

CVE-2026-18021 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Beaver Builder is a drag-and-drop website builder plugin for WordPress that allows users to create and customize pages visually. The plugin fails to properly validate user input before executing shortcodes, allowing unauthenticated attackers to run arbitrary shortcodes and potentially inject malicious content, modify page functionality, or access sensitive data.

Technical details

The vulnerability is an arbitrary shortcode execution flaw in Beaver Builder's handling of user-supplied values. The plugin processes an action without properly sanitizing or validating input before passing it to the do_shortcode() function, which executes shortcode handlers. This allows unauthenticated attackers to inject and execute arbitrary shortcodes over the network. Shortcode execution can lead to code execution depending on available shortcode handlers and their capabilities. A patch was released in version 2.10.3.2.

Affected products

  • Fastly Beaver Builder up to and including 2.10.3.1

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Fix available in version 2.10.3.2

References