PT-2025-49006 · WordPress · Beaver Builder – Wordpress Page Builder
Athiwat Tiprasaharn
+3
·
Publicado
2025-12-04
·
Atualizado
2025-12-04
·
CVE-2025-12782
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Beaver Builder – WordPress Page Builder plugin for WordPress versions prior to 2.9.4
Description
The Beaver Builder plugin for WordPress is susceptible to an authorization bypass issue. This occurs because the plugin does not adequately verify user authorization within the
disable() function. Authenticated attackers with contributor-level access or higher can disable Beaver Builder layouts on any post or page, leading to content integrity problems and layout disruptions.Recommendations
Update the Beaver Builder – WordPress Page Builder plugin to version 2.9.4 or later. As a temporary workaround, consider restricting access to the
disable() function until a patch is available.Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Beaver Builder – Wordpress Page Builder