PT-2026-31293 · WordPress · Beaver Builder Page Builder

Athiwat Tiprasaharn

+1

·

Published

2026-04-08

·

Updated

2026-04-12

·

CVE-2026-2481

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Beaver Builder Page Builder versions up to and including 2.10.1.1
Description The Beaver Builder Page Builder plugin for WordPress is susceptible to Stored Cross-Site Scripting through the settings[js] parameter due to inadequate input sanitization and output escaping. This allows authenticated attackers with author-level access or higher to inject malicious web scripts into pages, which will then execute when a user accesses the compromised page.
Recommendations Update Beaver Builder Page Builder to a version later than 2.10.1.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-2481

Affected Products

Beaver Builder Page Builder