
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69319 is a Code Injection (CWE-94) vulnerability in the Beaver Builder WordPress plugin (lite version) that allows authenticated attackers with Contributor-level or higher privileges to execute arbitrary code remotely. It affects all versions of the plugin through 2.9.4.1, with version 2.9.4.2 being the first patched release. The vulnerability was reported on November 10, 2025, and published by Patchstack on January 21–22, 2026. It carries a CVSS v3.1 base score of 7.5 (High), as assessed by CISA-ADP (Patchstack).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), meaning the plugin fails to properly sanitize or restrict user-controlled input before it is used in a code generation or evaluation context. Exploitation requires network access, low privileges (Contributor or Developer role), no user interaction, and is rated High complexity, suggesting some preconditions or non-trivial exploitation steps are involved. The flaw was discovered by security researcher 'mcdruid' and reported through Patchstack's responsible disclosure process (Patchstack).
Successful exploitation allows a remote, authenticated attacker to execute arbitrary code on the WordPress server hosting the vulnerable Beaver Builder plugin, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive data, modify site content or server files, install backdoors, or take full control of the WordPress installation. Given the plugin's widespread use as a page builder, compromise could extend to site visitors through injected malicious content or further lateral movement within shared hosting environments (Patchstack).
No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.029% (0.000290), indicating a currently low probability of exploitation in the wild. Patchstack notes that vulnerabilities of this class (Arbitrary Code Execution) are frequently used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity, and has issued a virtual patch/mitigation rule for its users. There is no current CISA KEV catalog listing for this CVE, and no specific threat actor attribution has been reported (Patchstack).
The vendor has released version 2.9.4.2 of the Beaver Builder plugin (both lite and premium versions), which resolves this vulnerability. Site administrators should update immediately to version 2.9.4.2 or later via the WordPress plugin dashboard. Patchstack users benefit from an automatically applied virtual patch rule that blocks exploitation attempts until the plugin is updated. If an immediate update is not possible, restricting Contributor-level user registration and limiting untrusted user roles can reduce exposure (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability report for the week of January 19–25, 2026, and Sucuri highlighted it in its January 2026 vulnerability patch roundup, indicating broad awareness within the WordPress security community. Patchstack, which discovered and disclosed the vulnerability, classified it as high priority and noted its potential for mass-exploit campaigns. No notable vendor statements beyond the patch release or significant social media controversy have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."