PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17090 beaverbuilder CVE debrief

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module 'button' (Button Code) Setting in all versions up to, and including, 2.10.2.2. This vulnerability is caused by insufficient input sanitization and output escaping, allowing authenticated attackers with author-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability affects WordPress installations with the Beaver Builder Page Builder plugin installed, particularly those with author-level access and above. To verify, defenders should review the plugin's input validation and output escaping mechanisms, particularly in the Button Module 'button' setting. Additionally, they should assess the impact of the vulnerability on their WordPress installations and prioritize patching or mitigating the vulnerability. Operators of WordPress platforms, vulnerability management teams, and security teams should be aware of this vulnerability and take necessary precautions to restrict user roles and capabilities or implement compensating controls. AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T04:18:15.940Z and has not been modified since then.

Vendor
beaverbuilder
Product
Beaver Builder Page Builder – Drag and Drop Website Builder
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

WordPress users with Beaver Builder Page Builder plugin installed, particularly those with author-level access and above, should be aware of this vulnerability. Operators of WordPress platforms, vulnerability management teams, and security teams should prioritize patching or mitigating this vulnerability. Additionally, users with the edit_posts capability, which includes authors and above by default in Beaver Builder, should take extra precautions to restrict user roles and capabilities or implement compensating controls.

Technical summary

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module 'button' (Button Code) Setting in all versions up to, and including, 2.10.2.2. The vulnerability is caused by insufficient input sanitization and output escaping. This allows authenticated attackers with author-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability can be exploited by users with author-level access and above, which includes users with the edit_posts capability by default in Beaver Builder. The plugin's default settings grant editor access to any WordPress role holding the edit_posts capability.

Defensive priority

Authenticated attackers with author-level access can inject web scripts via the Beaver Builder Page Builder plugin's Button Module 'button' setting.

Recommended defensive actions

  • Inventory and verify installed plugin versions
  • Restrict user roles and capabilities
  • Implement input validation and output encoding
  • Monitor for suspicious activity
  • Apply vendor patches or updates
  • Review compensating controls for exposed systems
  • Track exceptions and retest remediated assets

Evidence notes

The Beaver Builder Page Builder plugin for WordPress has a Stored Cross-Site Scripting vulnerability via Button Module 'button' setting due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with author-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability affects all versions up to, and including, 2.10.2.2. To verify, defenders should review the plugin's input validation and output escaping mechanisms, particularly in the Button Module 'button' setting. Additionally, they should assess the impact of the vulnerability on their WordPress installations and prioritize patching or mitigating the vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T04:18:15.940Z and has not been modified since then.