{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/beaver-builder-page-builder--2.11.0.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:beaver_builder:page_builder:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-92084"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=32816D9B-A055-59DB-B7CD-C30F29C64215\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Beaver Builder Page Builder (\u003c= 2.11.0.5)","Beaver Builder Lite (\u003c= 2.11.0.5)"],"_cs_severities":["critical"],"_cs_tags":["web-vulnerability","wordpress","plugin-exploit"],"_cs_type":"advisory","_cs_vendors":["Beaver Builder"],"content_html":"\u003cp\u003eThe Beaver Builder Page Builder plugin for WordPress (versions up to and including 2.11.0.5) contains a critical security flaw involving improper input validation. The vulnerability allows unauthenticated attackers to execute arbitrary shortcodes within a WordPress environment. This occurs because the plugin's Sidebar module fails to sanitize or validate user-supplied values before passing them to the do_shortcode function.\u003c/p\u003e\n\u003cp\u003eThe exploitation path relies on the presence of a Beaver Builder page utilizing the Sidebar module, which contains a widget capable of rendering attacker-controllable text, such as the WordPress core Recent Comments widget. If the target environment has comment moderation disabled or if an attacker's crafted comment is approved, the malicious shortcode payload is injected and subsequently executed when the Sidebar module renders the widget. Successful exploitation can lead to a range of impacts, including unauthorized data access or remote code execution, depending on the capabilities of the shortcodes enabled on the target site.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary shortcodes on affected WordPress installations. This can lead to unauthorized information disclosure, privilege escalation, or remote code execution depending on the specific shortcodes available within the site's environment. This vulnerability affects all sites running Beaver Builder version 2.11.0.5 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Beaver Builder Page Builder plugin to a version patched against CVE-2026-92084 immediately.\u003c/li\u003e\n\u003cli\u003eReview site configurations for WordPress instances running affected versions, specifically checking for the presence of the Sidebar module on publicly accessible pages.\u003c/li\u003e\n\u003cli\u003eImplement strict comment moderation policies on WordPress sites to prevent unauthorized or untrusted content from being rendered in widgets.\u003c/li\u003e\n\u003cli\u003eAudit currently enabled WordPress shortcodes to assess the potential risk of arbitrary execution in the event of an exploit attempt.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-04T12:06:37Z","date_published":"2026-10-03T08:54:12Z","id":"https://feed.craftedsignal.io/briefs/2026-10-beaver-builder-shortcode/","summary":"Beaver Builder Page Builder for WordPress (\u003c= 2.11.0.5) is vulnerable to unauthenticated arbitrary shortcode execution via improper input validation in the Sidebar module.","title":"Unauthenticated Arbitrary Shortcode Execution in Beaver Builder Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-beaver-builder-shortcode/"}],"language":"en","title":"CraftedSignal Threat Feed - Beaver Builder Page Builder (\u003c= 2.11.0.5)","version":"https://jsonfeed.org/version/1.1"}