Beaver Builder Plugin (Starter Version) <= 2.9.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'auto_play'
medium
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 2.9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level...
- CVSS:
- 6.4
- Affected:
- up to 2.9.2.1
- Fixed in:
- 2.9.3.1
- Disclosed:
- Oct 22, 2025
CVE-2025-8427 on NVD →
Beaver Builder Plugin (Starter Version) <= 2.9.1 - Authenticated (Administrator+) Arbitrary File Upload
high
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_enabled_icons' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to...
- CVSS:
- 7.2
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1.1
- Disclosed:
- Jun 19, 2025
CVE-2025-4102 on NVD →
Beaver Builder Plugin [bb-plugin] < 2.9.1.1
unknown
- Affected:
- up to 2.9.1.1
- Fixed in:
- 2.9.1.1
CVE-2025-4102 on NVD →
Beaver Builder Plugin [bb-plugin] < 2.9.3.1
unknown
- Affected:
- up to 2.9.3.1
- Fixed in:
- 2.9.3.1
CVE-2025-8427 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database