Arbitrary Shortcode Execution Vulnerability in Beaver Builder Page Builder Plugin for WordPress
CVE-2026-92084
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-92084?
The Beaver Builder Page Builder plugin for WordPress contains a vulnerability that permits unauthenticated attackers to execute arbitrary shortcodes. This flaw arises from insufficient validation of values prior to processing do_shortcode, notably within pages that leverage the Sidebar module. Attackers can exploit this by embedding their own text in a widget, which can lead to the execution of unauthorized commands if comment moderation settings are improperly configured.
Affected Version(s)
Beaver Builder Page Builder β Drag and Drop Website Builder 0 <= 2.11.0.5