<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Plugin-Exploit - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/plugin-exploit/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 08:54:12 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/plugin-exploit/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Arbitrary Shortcode Execution in Beaver Builder Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-beaver-builder-shortcode/</link><pubDate>Sat, 03 Oct 2026 08:54:12 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-beaver-builder-shortcode/</guid><description>Beaver Builder Page Builder for WordPress (&lt;= 2.11.0.5) is vulnerable to unauthenticated arbitrary shortcode execution via improper input validation in the Sidebar module.</description><content:encoded><![CDATA[<p>The Beaver Builder Page Builder plugin for WordPress (versions up to and including 2.11.0.5) contains a critical security flaw involving improper input validation. The vulnerability allows unauthenticated attackers to execute arbitrary shortcodes within a WordPress environment. This occurs because the plugin's Sidebar module fails to sanitize or validate user-supplied values before passing them to the do_shortcode function.</p>
<p>The exploitation path relies on the presence of a Beaver Builder page utilizing the Sidebar module, which contains a widget capable of rendering attacker-controllable text, such as the WordPress core Recent Comments widget. If the target environment has comment moderation disabled or if an attacker's crafted comment is approved, the malicious shortcode payload is injected and subsequently executed when the Sidebar module renders the widget. Successful exploitation can lead to a range of impacts, including unauthorized data access or remote code execution, depending on the capabilities of the shortcodes enabled on the target site.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary shortcodes on affected WordPress installations. This can lead to unauthorized information disclosure, privilege escalation, or remote code execution depending on the specific shortcodes available within the site's environment. This vulnerability affects all sites running Beaver Builder version 2.11.0.5 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the Beaver Builder Page Builder plugin to a version patched against CVE-2026-92084 immediately.</li>
<li>Review site configurations for WordPress instances running affected versions, specifically checking for the presence of the Sidebar module on publicly accessible pages.</li>
<li>Implement strict comment moderation policies on WordPress sites to prevent unauthorized or untrusted content from being rendered in widgets.</li>
<li>Audit currently enabled WordPress shortcodes to assess the potential risk of arbitrary execution in the event of an exploit attempt.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-vulnerability</category><category>wordpress</category><category>plugin-exploit</category></item></channel></rss>