Stored Cross-Site Scripting Vulnerability in Beaver Builder Drag and Drop Website Builder
CVE-2026-2481

6.4MEDIUM

What is CVE-2026-2481?

The Beaver Builder Page Builder plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping in the 'settings[js]' parameter. Authenticated users with author-level access or higher can exploit this vulnerability to inject malicious scripts into web pages, which will execute when other users visit the affected pages. This poses a significant risk as it allows for the potential manipulation of a site's content and user interactions, leading to data breaches or additional exploits.

Affected Version(s)

Beaver Builder Page Builder – Drag and Drop Website Builder 0 <= 2.10.1.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
Tharadol Suksamran
.