CVE-2026-92084 is a critical (CVSS 9.1) arbitrary shortcode execution flaw in the Beaver Builder Page Builder plugin for WordPress. It affects all versions up to and including 2.11.0.5.
What Is It
CVE-2026-92084 is a code injection weakness (CWE-94) in the Beaver Builder Page Builder – Drag and Drop Website Builder plugin. The NVD record says users can trigger an action that passes a value to do_shortcode without validating it first. This lets unauthenticated attackers run arbitrary shortcodes.
Exploitation has preconditions. The target site must have a Beaver Builder page that uses the Sidebar module. That module must contain a widget that displays text an attacker can control, such as the core Recent Comments widget. Comment moderation must also be turned off, or the attacker's comment must already be approved.
Why It Matters
Wordfence scored the flaw CVSS 3.1 9.1 (Critical) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. An attacker can exploit it over the network with low complexity, no privileges and no user interaction. The impact on confidentiality and integrity is high. There is no availability impact.
Anyone who can post a comment that shows up on the page may be able to run arbitrary shortcodes. The damage depends on which shortcodes are registered on the site.
Exploitation status: CVE-2026-92084 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The sources cited here do not confirm active exploitation.
What's Vulnerable
- Vendor: beaverbuilder
- Product: Beaver Builder Page Builder – Drag and Drop Website Builder (WordPress plugin)
- Affected versions: all versions up to and including 2.11.0.5
- Required conditions:
- a Beaver Builder page using the Sidebar module with a widget that shows attacker-controllable text
- comment moderation turned off, or an approved attacker comment
The NVD record does not list any CPEs yet. It was published on 2026-10-03 and its status is "Received."
Patch Status
The NVD record does not name a fixed version. Its references include a WordPress.org Trac changeset (3713226) to the Sidebar module in the plugin's trunk, which suggests a code fix is in progress. Check the Wordfence advisory or the plugin changelog to confirm a patched release.
Until you can confirm and install an update newer than 2.11.0.5: - Turn on comment moderation. - Check Beaver Builder pages that use the Sidebar module for widgets that display user-supplied text, such as Recent Comments.
The NVD and KEV data contain no CISA required action or due date.