PT-2025-49006 · WordPress · Beaver Builder – Wordpress Page Builder

Athiwat Tiprasaharn

+3

·

Published

2025-12-04

·

Updated

2025-12-04

·

CVE-2025-12782

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Beaver Builder – WordPress Page Builder plugin for WordPress versions prior to 2.9.4
Description The Beaver Builder plugin for WordPress is susceptible to an authorization bypass issue. This occurs because the plugin does not adequately verify user authorization within the disable() function. Authenticated attackers with contributor-level access or higher can disable Beaver Builder layouts on any post or page, leading to content integrity problems and layout disruptions.
Recommendations Update the Beaver Builder – WordPress Page Builder plugin to version 2.9.4 or later. As a temporary workaround, consider restricting access to the disable() function until a patch is available.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12782

Affected Products

Beaver Builder – Wordpress Page Builder