Beaver Builder Plugin Vulnerability Exposes WordPress Sites to XSS Attacks
A notable security flaw has been identified in the Beaver Builder Plugin (Starter Version) for WordPress. This vulnerability, tracked as CVE-2025-8427, is a Stored Cross-Site Scripting (XSS) issue. It stems from inadequate input handling and output encoding related to the ‘auto_play’ parameter within the plugin.
In simple terms, this means that if you’re using an affected version of the Beaver Builder plugin, an authenticated attacker—someone with at least Contributor-level access to your WordPress site—could sneak malicious code into your website. This hidden code would then run whenever another user visits a page where the code has been injected, potentially leading to unauthorized actions or data theft.
CVE Details
- Product: Beaver Builder Plugin (Starter Version) for WordPress
- Published: October 23, 2025
- Severity: Medium (CVSS Score: 6.4)
- Status: Analyzed
Affected Products
The Stored Cross-Site Scripting vulnerability affects the Beaver Builder Plugin (Starter Version) for WordPress in all versions up to, and including, 2.9.2.1.
Current Status
This vulnerability has been thoroughly analyzed, confirming its existence and potential impact on websites utilizing the affected plugin versions. Users are advised to take prompt action to secure their installations.
Severity Level
Rated as “Medium” severity with a CVSS score of 6.4, this vulnerability requires an attacker to have prior authentication to your WordPress site, specifically Contributor-level access or higher. While this access requirement lowers the immediate risk compared to vulnerabilities exploitable by unauthenticated users, the impact can still be significant. Successful exploitation could lead to defacement, redirection, session hijacking, or even further compromise of the website or its users. Understanding the potential risks is a crucial part of WordPress security best practices.
Possible Solutions
The good news is that a fix for this vulnerability is available. Users of the Beaver Builder Plugin (Starter Version) should update their installations immediately to version 2.9.3 or newer. According to the change logs, version 2.9.3 was released on August 14, 2025, and specifically addresses an XSS issue related to the “auto play” setting in the Testimonials Module, which aligns with the reported vulnerability.
Regularly updating your plugins is a fundamental step in maintaining a secure WordPress environment. For more information on preventing similar attacks, consider learning about understanding Cross-Site Scripting.
References
https://www.wordfence.com/threat-intel/vulnerabilities/id/afec9b5b-da37-4e12-935e-9d3bb3ca01f0?source=cve


