Beaver Builder Plugin Stored Cross-Site Scripting Vulnerability (CVE-2025-8427) — Medium Severity

Beaver Builder Plugin Vulnerability Exposes WordPress Sites to XSS Attacks

A notable security flaw has been identified in the Beaver Builder Plugin (Starter Version) for WordPress. This vulnerability, tracked as CVE-2025-8427, is a Stored Cross-Site Scripting (XSS) issue. It stems from inadequate input handling and output encoding related to the ‘auto_play’ parameter within the plugin.

In simple terms, this means that if you’re using an affected version of the Beaver Builder plugin, an authenticated attacker—someone with at least Contributor-level access to your WordPress site—could sneak malicious code into your website. This hidden code would then run whenever another user visits a page where the code has been injected, potentially leading to unauthorized actions or data theft.

CVE Details

  • Product: Beaver Builder Plugin (Starter Version) for WordPress
  • Published: October 23, 2025
  • Severity: Medium (CVSS Score: 6.4)
  • Status: Analyzed

Affected Products

The Stored Cross-Site Scripting vulnerability affects the Beaver Builder Plugin (Starter Version) for WordPress in all versions up to, and including, 2.9.2.1.

Current Status

This vulnerability has been thoroughly analyzed, confirming its existence and potential impact on websites utilizing the affected plugin versions. Users are advised to take prompt action to secure their installations.

Severity Level

Rated as “Medium” severity with a CVSS score of 6.4, this vulnerability requires an attacker to have prior authentication to your WordPress site, specifically Contributor-level access or higher. While this access requirement lowers the immediate risk compared to vulnerabilities exploitable by unauthenticated users, the impact can still be significant. Successful exploitation could lead to defacement, redirection, session hijacking, or even further compromise of the website or its users. Understanding the potential risks is a crucial part of WordPress security best practices.

Possible Solutions

The good news is that a fix for this vulnerability is available. Users of the Beaver Builder Plugin (Starter Version) should update their installations immediately to version 2.9.3 or newer. According to the change logs, version 2.9.3 was released on August 14, 2025, and specifically addresses an XSS issue related to the “auto play” setting in the Testimonials Module, which aligns with the reported vulnerability.

Regularly updating your plugins is a fundamental step in maintaining a secure WordPress environment. For more information on preventing similar attacks, consider learning about understanding Cross-Site Scripting.

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/afec9b5b-da37-4e12-935e-9d3bb3ca01f0?source=cve

Change Logs

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.