Junglewise Threat Intelligence

CVE-2026-2481: Beaver Builder Page Builder Stored XSS in settings[js] parameter

CVE-2026-2481 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Executive brief

Beaver Builder is a popular WordPress plugin used to design websites through a drag-and-drop interface. A security vulnerability in this plugin allows users with 'Author' level permissions or higher to inject malicious scripts into website pages. When other users or visitors view these compromised pages, the scripts can execute automatically, potentially leading to unauthorized actions or data theft.

Technical details

The Beaver Builder Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'settings[js]' parameter. This vulnerability allows authenticated attackers with author-level permissions or higher to inject arbitrary web scripts into pages. Because the scripts are stored on the server, they will execute in the browser of any user who navigates to the affected page. The vulnerability is present in all versions up to and including 2.10.1.1. While the provided changelog mentions various security fixes in later versions (such as 2.10.1.3 and 2.10.3.1), users should ensure they are running the latest available version to mitigate these risks.

Affected products

  • Beaver Builder Beaver Builder Page Builder – Drag and Drop Website Builder up to, and including, 2.10.1.1

Timeline

  • 2026-04-08: disclosed: Initial publication date
  • 2026-04-08: advisory: Wordfence published vulnerability details

References

Related threats