CVE-2026-92084: Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to unauthenticated exploitation?
A site must be running Beaver Builder Page Builder version 2.11.0.5 or earlier and have a Beaver Builder page containing a Sidebar module. That module must be populated with a widget that can display attacker-controlled text, such as the core Recent Comments widget.
What must an attacker do to trigger the issue?
The attacker needs attacker-controlled text to be displayed by the widget used in the Sidebar module. For the Recent Comments widget example, this requires comment moderation to be disabled or the attacker’s comment to be approved.
Are sites protected if comments require moderation?
Comment moderation can prevent an attacker’s unapproved comment from being displayed through the Recent Comments widget. However, the affected condition remains possible if an attacker-controlled comment is approved or another widget in the Sidebar module displays attacker-controlled text.
How can administrators check whether they are affected?
Check whether Beaver Builder pages use the Sidebar module, then identify the widget configured in that module and whether it renders text that unauthenticated users can influence. In particular, review Recent Comments widgets and the site’s comment moderation and approval settings.