A security flaw has been found in the popular Beaver Builder WordPress plugin that could allow attackers to run malicious code on websites. This type of vulnerability, known as Reflected Cross-Site Scripting (XSS), means that if a user clicks on a specially crafted link, their browser could execute harmful scripts. This is particularly concerning because it can happen even if the attacker is not logged in to your site.
CVE Details
- Product: Beaver Builder – WordPress Page Builder plugin
- Published: August 28, 2025
- Severity: Medium
- Status: Analyzed
Affected Products
The Reflected Cross-Site Scripting vulnerability impacts all versions of the Beaver Builder – WordPress Page Builder plugin up to and including version 2.9.2.1.
Current Status
This vulnerability has been thoroughly analyzed. A patch has been released by the developers to address the issue, incorporating proper input sanitization and output escaping to prevent malicious script injection.
Severity Level
Rated as “Medium” severity, this vulnerability poses a significant risk. While not the highest level, it can still lead to serious consequences if exploited. Attackers could potentially steal sensitive information from users, deface websites, or redirect visitors to malicious sites by tricking them into clicking a link.
Possible Solutions
The most important step is to update your Beaver Builder – WordPress Page Builder plugin immediately. The developers have released a fix in version 2.9.3.1. Ensure your plugin is updated to this version or newer to protect your website. Regularly updating all your WordPress plugins, themes, and core software is a critical security practice to keep your site safe from known vulnerabilities.
References
https://plugins.trac.wordpress.org/changeset/3350565/beaver-builder-lite-version/trunk/includes/ui-iframe.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/93504959-2154-4b8c-a7d1-c982bdc8d034?source=cve


