Arbitrary Shortcode Execution in Beaver Builder Plugin for WordPress
CVE-2026-18021

6.5MEDIUM

What is CVE-2026-18021?

The Beaver Builder Page Builder plugin for WordPress is susceptible to a vulnerability that allows for arbitrary shortcode execution due to improper validation of values when invoking the do_shortcode function. This flaw exists in all versions up to and including 2.10.3.1, making it possible for unauthorized users to run arbitrary shortcodes, which could lead to various security implications.

Affected Version(s)

Beaver Builder Page Builder – Drag and Drop Website Builder 0 <= 2.10.3.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kishan Vyas
.