
POC: CVE-2026-92084: Beaver Builder Lite <= 2.11.0.5 — unauthenticated shortcode execution (CVSS 9.1). Comment author name → Recent Comments widget → BB Sidebar module → layout-wide do_shortcode() fires it server-side on every page view. Vendor fix: one missing line. Full repro lab: https://github.com/Hassham1/CVE-2026-92084-beaver-builder-shortcode-poc


