CVE advisoryCRITICAL
CVE-2026-92084
WordPress Beaver Builder Arbitrary Shortcode Execution Vulnerability.
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
A vulnerability in the WordPress Beaver Builder plugin allows unauthenticated attackers to execute arbitrary shortcodes, potentially leading to compromise. This occurs when specific conditions are met regarding page content and widget configuration. The plugin's failure to validate input before processing with `do_shor