PT-2025-49006 · WordPress · Beaver Builder – Wordpress Page Builder

Athiwat Tiprasaharn

+3

·

Publicado

2025-12-04

·

Atualizado

2025-12-04

·

CVE-2025-12782

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Beaver Builder – WordPress Page Builder plugin for WordPress versions prior to 2.9.4
Description The Beaver Builder plugin for WordPress is susceptible to an authorization bypass issue. This occurs because the plugin does not adequately verify user authorization within the disable() function. Authenticated attackers with contributor-level access or higher can disable Beaver Builder layouts on any post or page, leading to content integrity problems and layout disruptions.
Recommendations Update the Beaver Builder – WordPress Page Builder plugin to version 2.9.4 or later. As a temporary workaround, consider restricting access to the disable() function until a patch is available.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12782

Produtos afetados

Beaver Builder – Wordpress Page Builder