Cyber & AI intelligence
Wasteland.
Briefs indexed2992
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-92084 2026-10-03

Beaver Builder WordPress Plugin Flaw Lets Unauthenticated Attackers Run Arbitrary Shortcodes (CVE-2026-92084)

"CVE-2026-92084 is a critical (CVSS 9.1) arbitrary shortcode execution flaw in the Beaver Builder Page Builder plugin for WordPress. It affects all versions up to and including 2.11.0.5."

CVE-2026-92084 is a critical (CVSS 9.1) arbitrary shortcode execution flaw in the Beaver Builder Page Builder plugin for WordPress. It affects all versions up to and including 2.11.0.5.

What Is It

CVE-2026-92084 is a code injection weakness (CWE-94) in the Beaver Builder Page Builder – Drag and Drop Website Builder plugin. The NVD record says users can trigger an action that passes a value to do_shortcode without validating it first. This lets unauthenticated attackers run arbitrary shortcodes.

Exploitation has preconditions. The target site must have a Beaver Builder page that uses the Sidebar module. That module must contain a widget that displays text an attacker can control, such as the core Recent Comments widget. Comment moderation must also be turned off, or the attacker's comment must already be approved.

Why It Matters

Wordfence scored the flaw CVSS 3.1 9.1 (Critical) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. An attacker can exploit it over the network with low complexity, no privileges and no user interaction. The impact on confidentiality and integrity is high. There is no availability impact.

Anyone who can post a comment that shows up on the page may be able to run arbitrary shortcodes. The damage depends on which shortcodes are registered on the site.

Exploitation status: CVE-2026-92084 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The sources cited here do not confirm active exploitation.

What's Vulnerable

The NVD record does not list any CPEs yet. It was published on 2026-10-03 and its status is "Received."

Patch Status

The NVD record does not name a fixed version. Its references include a WordPress.org Trac changeset (3713226) to the Sidebar module in the plugin's trunk, which suggests a code fix is in progress. Check the Wordfence advisory or the plugin changelog to confirm a patched release.

Until you can confirm and install an update newer than 2.11.0.5: - Turn on comment moderation. - Check Beaver Builder pages that use the Sidebar module for widgets that display user-supplied text, such as Recent Comments.

The NVD and KEV data contain no CISA required action or due date.

Sources