Executive brief
Beaver Builder is a popular WordPress plugin used to design websites through a drag-and-drop interface. A security vulnerability in this plugin allows users with 'Author' level permissions or higher to inject malicious scripts into website pages. When other users or visitors view these compromised pages, the scripts can execute automatically, potentially leading to unauthorized actions or data theft.
Technical details
The Beaver Builder Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'settings[js]' parameter. This vulnerability allows authenticated attackers with author-level permissions or higher to inject arbitrary web scripts into pages. Because the scripts are stored on the server, they will execute in the browser of any user who navigates to the affected page. The vulnerability is present in all versions up to and including 2.10.1.1. While the provided changelog mentions various security fixes in later versions (such as 2.10.1.3 and 2.10.3.1), users should ensure they are running the latest available version to mitigate these risks.
Affected products
- Beaver Builder Beaver Builder Page Builder – Drag and Drop Website Builder up to, and including, 2.10.1.1
Timeline
- 2026-04-08: disclosed: Initial publication date
- 2026-04-08: advisory: Wordfence published vulnerability details