CVE-2026-92084

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-10-03); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-10-03: 2Mentions · 2026-10-04: 110-0310-04
Referenced assets3 URLs
Full discourse3 posts
  • Muhammad Hassham@Ro0t_Hassh

    POC: CVE-2026-92084: Beaver Builder Lite <= 2.11.0.5 — unauthenticated shortcode execution (CVSS 9.1). Comment author name → Recent Comments widget → BB Sidebar module → layout-wide do_shortcode() fires it server-side on every page view. Vendor fix: one missing line. Full repro lab: https://github.com/Hassham1/CVE-2026-92084-beaver-builder-shortcode-poc

    0000013
    185 followersView on X
  • CVE@CVEnew

    CVE-2026-92084 The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc… https://www.cve.org/CVERecord?id=CVE-2026-92084

    000001.6K
    58.1K followersView on X
  • Severity Daily@severitydaily

    A commenter's display name could run shortcodes on 100,000+ Beaver Builder sites. The flag that stops it shipped in July and was never set on the Sidebar module. Patched, no exploitation reported. https://severitydaily.com/beaver-builder-cve-2026-92084-renders-shortcodes-default-sidebar-module-recent-comments/

    0000022
    31 followersView on X

Explore more