CRITICAL 9.1 CVE-2026-92084 Published 3 Oct 2026

Beaver Builder WordPress Plugin Arbitrary Shortcode Execution Vulnerability

Worried this affects your website?

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution.

  • Affects all versions up to, and including, 2.11.0.5.
  • Due to an action that does not properly validate a value before running do_shortcode.
  • Allows unauthenticated attackers to execute arbitrary shortcodes.
  • Requires a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget.
  • Requires comment moderation to be disabled or the attacker's comment to be approved.

Reference: CVE-2026-92084 on NVD

← Back to Security News