PT-2025-49006 · WordPress · Beaver Builder – Wordpress Page Builder
Athiwat Tiprasaharn
+3
·
Published
2025-12-04
·
Updated
2025-12-04
·
CVE-2025-12782
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Beaver Builder – WordPress Page Builder plugin for WordPress versions prior to 2.9.4
Description
The Beaver Builder plugin for WordPress is susceptible to an authorization bypass issue. This occurs because the plugin does not adequately verify user authorization within the
disable() function. Authenticated attackers with contributor-level access or higher can disable Beaver Builder layouts on any post or page, leading to content integrity problems and layout disruptions.Recommendations
Update the Beaver Builder – WordPress Page Builder plugin to version 2.9.4 or later. As a temporary workaround, consider restricting access to the
disable() function until a patch is available.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Beaver Builder – Wordpress Page Builder