Beaver Builder ≤2.11.0.5 allows unauthenticated shortcode execution (CVE-2026-92084)
The Beaver Builder page builder plugin, versions ≤ 2.11.0.5, contains an unauthenticated shortcode execution vulnerability (CVE-2026-92084, CVSS 9.1) via the Sidebar module. A public proof-of-concept is circulating, which dramatically raises the odds of mass exploitation.
What to do
- Update to 2.11.0.6 or later immediately.
- If you cannot update right away, restrict access to the site or disable the plugin until you can. Unauthenticated means anyone on the internet can try it.
- After updating, scan uploads and plugin directories for unexpected files and review for newly created admin accounts.
Page-builder plugins are high-value targets precisely because they run on so many sites. ZeroBreach inventories every plugin on every app it watches and flags vulnerable versions on its recurring scans.