
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18021 is an arbitrary shortcode execution vulnerability in the Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress. It affects all versions up to and including 2.10.3.1, allowing unauthenticated attackers to execute arbitrary shortcodes via a network-accessible action that fails to properly validate input before calling do_shortcode. The vulnerability was published on September 8, 2026, and assigned a CVSS v3.1 base score of 6.5 (Medium), with the CVE assigned by Wordfence (GitHub Advisory, Wordfence).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The plugin exposes a WordPress action handler that invokes do_shortcode on user-supplied input without adequate validation or sanitization, specifically in class-fl-builder.php around line 2018. Because no authentication or privilege check is enforced before this action is triggered, any unauthenticated remote attacker can craft an HTTP request to invoke arbitrary registered WordPress shortcodes (GitHub Advisory, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to execute arbitrary WordPress shortcodes, which can result in limited confidentiality and integrity impacts — such as accessing sensitive data exposed by shortcodes (e.g., user information, private content) and modifying site content. Availability is not directly impacted. The actual severity depends on which shortcodes are registered on the target site, as some third-party shortcodes may expose more sensitive functionality (GitHub Advisory, Wordfence).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment notes the attack is automatable with no exploitation observed. The EPSS score is approximately 0.27% (19th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
do_shortcode without proper input validation (referenced in class-fl-builder.php around line 2018)./wp-admin/admin-ajax.php) with the appropriate action parameter and a payload containing the desired shortcode tag (e.g., [some_shortcode]).do_shortcode, and executes the specified shortcode — potentially returning sensitive data or triggering content modification depending on the shortcodes available on the target site (GitHub Advisory, WordPress Trac)./wp-admin/admin-ajax.php with Beaver Builder-specific action parameters and shortcode-like content in the request body.admin-ajax.php from a single IP or user agent without a valid session cookie; unexpected shortcode output in server responses.Update the Beaver Builder Page Builder plugin to version 2.10.3.2 or later, which contains the fix for this vulnerability (WordPress Changeset). As a temporary workaround, site administrators can disable the plugin until the update is applied, or restrict access to wp-admin/admin-ajax.php for unauthenticated users via a web application firewall (WAF) rule. Wordfence users may benefit from firewall rules that detect and block exploitation attempts (Wordfence).
The vulnerability was reported and disclosed by Wordfence, which maintains a threat intelligence database for WordPress plugin vulnerabilities. No notable independent researcher commentary or significant social media discussion has been identified at this time (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."