Reflected Cross-Site Scripting Vulnerability in Beaver Builder Plugin for WordPress
CVE-2026-18843
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2026-18843?
The Beaver Builder Plugin (Starter Version) for WordPress exposes users to a Reflected Cross-Site Scripting (XSS) vulnerability through an insufficient input sanitization in the 'no_results_message' parameter. Attackers can exploit this flaw on all versions up to 2.11.0.1, potentially injecting malicious scripts into pages. Once the scripts are executed by an unsuspecting user, it can lead to unauthorized actions and compromised data, especially if the victim is tricked into clicking a malicious link.
Affected Version(s)
Beaver Builder Plugin (Starter Version) 0 <= 2.11.0.1