Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.4

Beaver Builder Plugin Allows Malicious Code Injection

CVE-2026-2481
Summary

The Beaver Builder plugin for WordPress has a security flaw that lets attackers inject malicious code into website pages. This could allow an attacker to take control of a website's content or steal user data. Website owners should update the Beaver Builder plugin to the latest version to fix this issue.

Original title
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings[js]' parameter in versions up to, and including, ...
Original description
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings[js]' parameter in versions up to, and including, 2.10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
nvd CVSS3.1 6.4
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 8 Apr 2026 · Updated: 9 Apr 2026 · First seen: 8 Apr 2026