Pricing
Case studies
Login
Start trial
Beaver Builder
Beaver Builder
Developer
2.10.1.2
Latest version
100,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
31 patched
6 Mitigation rules
WordPress Beaver Builder Page Builder - Drag and Drop Website Builder plugin <= 2.10.0.5 - Authenticated (Custom+) Missing Authorization to Stored Cross-Site Scripting via Global Settings vulnerability
<= 2.10.0.5
10/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.7.4.2
03/02/2026
Arbitrary Code Execution vulnerability
<= 2.9.4.1
21/01/2026
Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update vulnerability
<= 2.9.4.1
23/12/2025
Authenticated (Contributor+) Sensitive Information Exposure vulnerability
<= 2.9.4
09/12/2025
Missing Authorization to Authenticated (Contributor+) Builder Status Tampering vulnerability
<= 2.9.4
04/12/2025
Missing Authorization to Authenticated (Contributor+) Global Preset Modification vulnerability
<= 2.9.4
01/12/2025
Reflected Cross-Site Scripting vulnerability
<= 2.9.2.1
27/08/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.8.4.4
12/12/2024
Cross Site Scripting (XSS) vulnerability
<= 2.8.4.3
02/12/2024
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Widget vulnerability
<= 2.8.4.2
29/10/2024
Cross Site Scripting (XSS) vulnerability
<= 2.8.3.7
24/10/2024
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Group Module vulnerability
<= 2.8.3.6
27/09/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter vulnerability
<= 2.8.3.5
29/08/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 2.8.3.2
26/08/2024
Cross Site Scripting (XSS) vulnerability
<= 2.8.2.2
04/07/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via photo widget crop attribute vulnerability
<= 2.8.1.2
10/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.8.1.1
07/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Button vulnerability
<= 2.8.0.5
02/04/2024
Cross Site Scripting (XSS) vulnerability
<= 2.7.4.4
28/03/2024
Authenticated(Contributor+) Stored Cross-Site Scripting via heading tag vulnerability
<= 2.7.4.4
12/03/2024
Authenticated(Contributor+) Stored Cross-Site Scripting via Audio Widget vulnerability
<= 2.7.4.2
28/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget vulnerability
<= 2.7.4.2
21/02/2024
Reflected (DOM-Based) Cross-Site Scripting vulnerability
<= 2.7.4.2
21/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.7.4.2
21/02/2024
Cross Site Scripting (XSS) vulnerability
<= 2.7.2
26/12/2023
Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Caption On Hover
<= 2.5.5.2
30/08/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability via caption
<= 2.5.5.2
30/08/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Image URL
<= 2.5.5.2
29/08/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Text Editor
<= 2.5.5.2
29/08/2022
Broken Access Control vulnerability
<= 2.5.4.3
20/07/2022