ZeroBreach Request early access
← All security news
critical CVE-2026-92084

Beaver Builder ≤2.11.0.5 allows unauthenticated shortcode execution (CVE-2026-92084)

Tags: wordpress, plugin, beaver-builder, shortcode

The Beaver Builder page builder plugin, versions ≤ 2.11.0.5, contains an unauthenticated shortcode execution vulnerability (CVE-2026-92084, CVSS 9.1) via the Sidebar module. A public proof-of-concept is circulating, which dramatically raises the odds of mass exploitation.

What to do

  • Update to 2.11.0.6 or later immediately.
  • If you cannot update right away, restrict access to the site or disable the plugin until you can. Unauthenticated means anyone on the internet can try it.
  • After updating, scan uploads and plugin directories for unexpected files and review for newly created admin accounts.

Page-builder plugins are high-value targets precisely because they run on so many sites. ZeroBreach inventories every plugin on every app it watches and flags vulnerable versions on its recurring scans.