Beaver Builder Plugin (Lite Version) <= 2.9.2.1 - Reflected Cross-Site Scripting
Beaver Builder Page Builder – Drag and Drop Website Builder
Minimum safe version
2.10.1.5
Update to 2.10.1.5 or later to address 34 fixable vulnerabilities
CVE-2026-40744
Beaver Builder Page Builder – Drag and Drop Website Builder <= 2.10.0.5 - Authenticated (Custom+) Missing Authorization to Stored Cross-Site Scripting via Global Settings
Beaver Builder Page Builder – Drag and Drop Website Builder <= 2.10.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'settings[js]'
CVE-2025-69319
CVE-2025-12934
CVE-2025-12558
CVE-2025-12782
CVE-2025-11726
CVE-2024-11832
CVE-2024-53797
CVE-2024-9505
CVE-2024-50430
CVE-2024-9049
CVE-2024-7895
CVE-2024-43926
CVE-2024-37500
CVE-2024-4430
CVE-2024-3923
CVE-2024-2925
CVE-2024-30425
CVE-2024-1080
CVE-2024-1074
CVE-2024-0896
CVE-2024-1038
CVE-2024-0871
CVE-2024-0897
WordPress Beaver Builder Plugin <= 2.7.2 is vulnerable to Cross Site Scripting (XSS)
Beaver Builder – WordPress Page Builder (Free & Pro) <= 1.7 - Authorization Bypass
WordPress Beaver Builder Plugin <= 2.5.4.3 is vulnerable to Broken Access Control
CVE-2022-2695
CVE-2022-2517
CVE-2022-2934
CVE-2022-2716