CVE-2026-18021: Beaver Builder Page Builder <= 2.10.3.1 - Unauthenticated Arbitrary Shortcode Execution
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.10.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
Beaver Builder Page Builder for WordPress is affected in all versions up to and including 2.10.3.1. The referenced change set is for version 2.10.3.2, indicating that version as the available fixed release.
Does exploitation require an account or user interaction?
No. The supplied CVSS vector identifies network access, low attack complexity, no privileges required, and no user interaction, so an unauthenticated remote attacker can attempt exploitation.
What can an attacker do through this issue?
An attacker can execute arbitrary WordPress shortcodes because a value is not properly validated before it is passed to do_shortcode. The stated impact includes low confidentiality and integrity impact, with no availability impact.