CVE-2025-11726: Beaver Builder – WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Global Preset Modification
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.9.4. This is due to insufficient capability checks in the REST API endpoints under the 'fl-controls/v1' namespace that control site-wide Global Presets. This makes it possible for authenticated attackers with contributor-level access and above to add, modify, or delete global color and background presets that affect all Beaver Builder content site-wide.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11726?
CVE-2025-11726 is classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-11726?
To fix CVE-2025-11726, update the Beaver Builder – WordPress Page Builder plugin to version 2.9.5 or later.
What types of attacks can CVE-2025-11726 facilitate?
CVE-2025-11726 can facilitate unauthorized actions and data access through the affected REST API endpoints.
Is CVE-2025-11726 present in all versions of the Beaver Builder plugin?
CVE-2025-11726 affects all versions of the Beaver Builder plugin up to and including 2.9.4.
Who is affected by CVE-2025-11726?
Anyone using the Beaver Builder – WordPress Page Builder plugin version 2.9.4 or earlier is affected by CVE-2025-11726.