Input validation vulnerability in Beaver Builder Plugin (Starter Version) 2.9.2.1

The Beaver Builder Plugin (Starter Version) for WordPress is at risk of being hacked through a method called Stored Cross-Site Scripting. This can happen if someone uses the ‘auto_play’ feature, which is available in versions 2.9.2.1 and earlier. The plugin does not have enough protection in place to prevent harmful code from being inserted into web pages. This means that someone who is logged in and has Contributor-level access or higher can add dangerous code to a page that will run when someone else visits that page.

Detected in:

Beaver Builder Plugin (Starter Version) fixed vulnerable versions: >= * <= 2.9.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.