Arbitrary Shortcode Execution in Beaver Builder Plugin for WordPress
CVE-2026-18021
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-18021?
The Beaver Builder Page Builder plugin for WordPress is susceptible to a vulnerability that allows for arbitrary shortcode execution due to improper validation of values when invoking the do_shortcode function. This flaw exists in all versions up to and including 2.10.3.1, making it possible for unauthorized users to run arbitrary shortcodes, which could lead to various security implications.
Affected Version(s)
Beaver Builder Page Builder β Drag and Drop Website Builder 0 <= 2.10.3.1