External risk intelligence

WordPress Beaver Builder Arbitrary Shortcode Execution Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-92084

The vulnerability exists in a WordPress plugin designed for public-facing websites. As a page builder component, it operates within the frontend web environment, making it reachable by any internet user visiting the site.

Code Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Beaver Builder Page Builder plugin for WordPress, affecting its ability to properly validate user input. This flaw allows unauthenticated attackers to execute arbitrary commands, potentially leading to significant compromise of affected websites. The main concern is confirming relevance and exposure.

  • Unauthenticated attackers can execute commands.
  • Affects WordPress sites using Beaver Builder.
  • Confirm relevance and potential impact.

Attack Path

How an attacker could exploit the issue

An attacker can execute arbitrary shortcodes on a WordPress site without needing an account, provided the site uses the Beaver Builder plugin and has a specific configuration. This involves an attacker finding a Beaver Builder page that includes a Sidebar module containing a widget displaying user-controlled text, such as the Recent Comments widget. If comment moderation is off or the attacker's comment is approved, they can trigger the vulnerability by submitting specially crafted text. The underlying issue is the plugin's failure to properly validate input before processing it with the `do_shortcode` function, allowing the attacker to run malicious shortcodes.

  • Unauthenticated attackers can reach the site.
  • Malicious text is processed as shortcode.
  • Arbitrary code execution is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to execute arbitrary shortcodes on a WordPress site, provided the site has a specific page builder configuration. This could lead to the execution of malicious code or unintended actions within the website's context.

  • Website content and functionality at risk.
  • Execution via specially crafted user input.
  • Malicious code execution on the site.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Beaver Builder Page Builder WordPress plugin likely impacts websites using this tool for content creation. Website owners or their designated administrators, potentially supported by infrastructure or platform teams, should take the first step by identifying all WordPress instances using Beaver Builder. Confirming exposure and business criticality will guide prioritization and inform the need for vendor coordination or other immediate risk reduction measures.

  • Website owners should own this issue.
  • Verify if affected sites are publicly accessible.
  • Plan remediation based on verified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Beaver Builder plugin used for in WordPress?

Beaver Builder is a drag-and-drop page builder plugin that allows users to design custom website layouts visually without needing to write code. It acts as an extension to the core WordPress editor, enabling the creation of complex page structures and content modules, such as sidebars containing widgets, directly within the site's interface.

What does arbitrary shortcode execution mean for CVE-2026-92084?

This vulnerability is classified as CWE-94, which relates to code injection. In this context, it means the plugin fails to sanitize user input before passing it to a WordPress function that executes shortcodes. Because this validation is missing, an attacker can input specially crafted text that the system interprets as a functional command, allowing them to force the site to run unauthorized shortcodes.

How can an attacker trigger this vulnerability?

To trigger this bug, an attacker must find a Beaver Builder page configured with a Sidebar module that displays user-controllable text, such as a Recent Comments widget. The vulnerability does not trigger if the site lacks this specific module configuration or if there is no path for the attacker to input text—such as comments being disabled or strictly moderated.

Why is this CVE considered relevant for my WordPress site?

According to Halo Surface Signal, this vulnerability is very likely to be reachable because Beaver Builder is designed for public-facing websites. Since the plugin operates in the frontend web environment, any internet user can attempt to interact with the vulnerable Sidebar module, making publicly accessible sites particularly important to review for potential exposure.

What is the first step to address this issue?

If you use Beaver Builder, start by creating an inventory of all your WordPress instances where the plugin is installed. Once identified, verify which sites are publicly accessible and check if they utilize the specific Sidebar module configuration described in the advisory. This will help you determine the risk level and prioritize the necessary updates or mitigation steps.

References