CVE-2024-7895: Beaver Builder (Lite Version) <= 2.8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, and including, 2.8.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7895?
CVE-2024-7895 is classified as a moderate severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2024-7895?
To mitigate CVE-2024-7895, update the Beaver Builder plugin to version 2.8.3.6 or higher where the vulnerability has been addressed.
What type of vulnerability is CVE-2024-7895?
CVE-2024-7895 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2024-7895?
Any user running Beaver Builder versions up to and including 2.8.3.5 is affected by CVE-2024-7895.
Can CVE-2024-7895 be exploited by unauthenticated users?
CVE-2024-7895 requires authentication which means only authenticated users can exploit this vulnerability.