CVE-2026-18843
Received Received - Intake

Reflected Cross-Site Scripting in Beaver Builder Plugin

Vulnerability report for CVE-2026-18843, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: Wordfence

Description

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpbeaverbuilder beaver_builder_plugin to 2.11.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Beaver Builder Plugin (Starter Version) for WordPress has a reflected cross-site scripting (XSS) vulnerability. This flaw exists in versions up to and including 2.11.0.1 due to insufficient input sanitization and output escaping in the 'no_results_message' node_preview parameter. Attackers can exploit this to inject malicious scripts into web pages. If a user clicks a specially crafted link, the injected script executes in their browser.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using Beaver Builder Plugin (Starter Version) up to 2.11.0.1. Check for reflected XSS via the 'no_results_message' parameter in node_preview. Manually review plugin versions and test inputs for unsanitized parameters. No specific commands are provided in the context.

Impact Analysis

This vulnerability allows unauthenticated attackers to inject arbitrary web scripts into pages. If you click a malicious link, the injected script could steal cookies, session tokens, or other sensitive data. It may also perform actions on your behalf, such as changing settings or redirecting you to phishing sites. Users of affected WordPress sites with the vulnerable plugin should update immediately.

Compliance Impact

This XSS vulnerability could lead to unauthorized data access or modification, violating GDPR's data protection principles and HIPAA's security requirements. If exploited, it may result in data breaches, triggering compliance violations, fines, or legal consequences for organizations handling sensitive user data.

Mitigation Strategies

Immediately update the Beaver Builder Plugin to the latest version beyond 2.11.0.1. If updates are unavailable, disable the plugin temporarily or restrict access to untrusted users. Monitor for suspicious activity and apply WordPress hardening measures like input sanitization.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18843. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart