CRITICAL
9.1 CVE-2026-92084 Published 3 Oct 2026
Beaver Builder WordPress Plugin Arbitrary Shortcode Execution Vulnerability
Worried this affects your website?
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution.
- Affects all versions up to, and including, 2.11.0.5.
- Due to an action that does not properly validate a value before running do_shortcode.
- Allows unauthenticated attackers to execute arbitrary shortcodes.
- Requires a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget.
- Requires comment moderation to be disabled or the attacker's comment to be approved.
Reference: CVE-2026-92084 on NVD
← Back to Security News