CVE-2026-2481: Beaver Builder Page Builder – Drag and Drop Website Builder <= 2.10.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'settings[js]'
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings[js]' parameter in versions up to, and including, 2.10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2481?
CVE-2026-2481 has a medium severity rating due to the potential for authenticated stored cross-site scripting.
How do I fix CVE-2026-2481?
To fix CVE-2026-2481, update the Beaver Builder Page Builder plugin to version 2.10.1.2 or later.
What are the potential impacts of CVE-2026-2481?
The impacts of CVE-2026-2481 include the risk of attackers being able to execute arbitrary JavaScript in the context of the user's session.
Who is affected by CVE-2026-2481?
CVE-2026-2481 affects users of Beaver Builder Page Builder versions up to and including 2.10.1.1.
Is CVE-2026-2481 a common vulnerability?
CVE-2026-2481 is a specific vulnerability within the Beaver Builder plugin and may be relatively common among WordPress plugins that allow user input.