Beaver Builder Reflected Cross-Site Scripting Vulnerability (CVE-2025-8897) — Medium Severity

A security flaw has been found in the popular Beaver Builder WordPress plugin that could allow attackers to run malicious code on websites. This type of vulnerability, known as Reflected Cross-Site Scripting (XSS), means that if a user clicks on a specially crafted link, their browser could execute harmful scripts. This is particularly concerning because it can happen even if the attacker is not logged in to your site.

CVE Details

  • Product: Beaver Builder – WordPress Page Builder plugin
  • Published: August 28, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

The Reflected Cross-Site Scripting vulnerability impacts all versions of the Beaver Builder – WordPress Page Builder plugin up to and including version 2.9.2.1.

Current Status

This vulnerability has been thoroughly analyzed. A patch has been released by the developers to address the issue, incorporating proper input sanitization and output escaping to prevent malicious script injection.

Severity Level

Rated as “Medium” severity, this vulnerability poses a significant risk. While not the highest level, it can still lead to serious consequences if exploited. Attackers could potentially steal sensitive information from users, deface websites, or redirect visitors to malicious sites by tricking them into clicking a link.

Possible Solutions

The most important step is to update your Beaver Builder – WordPress Page Builder plugin immediately. The developers have released a fix in version 2.9.3.1. Ensure your plugin is updated to this version or newer to protect your website. Regularly updating all your WordPress plugins, themes, and core software is a critical security practice to keep your site safe from known vulnerabilities.

References

https://plugins.trac.wordpress.org/changeset/3350565/beaver-builder-lite-version/trunk/includes/ui-iframe.php

https://www.wordfence.com/threat-intel/vulnerabilities/id/93504959-2154-4b8c-a7d1-c982bdc8d034?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.