CVE-2024-9505

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<h4>The Professional&#8217;s Choice for Drag &amp; Drop WordPress Page Building. Fast, Reliable, and Trusted since 2014</h4> <p>Beaver Builder is the page builder and website builder that agencies and developers rely on. Create pixel-perfect websites with our visual editor &#8211; no coding required. Front-end editing, flexible templates, and enterprise-grade performance. Try <a href="https://www.wpbeaverbuilder.com/pricing/" title="Get Beaver Builder Pro" rel="nofollow ugc">Beaver Builder Pro</a> for unlimited sites and premium features.</p> <h4>What Is The Beaver Builder Page Builder?</h4> <p>Beaver Builder is a flexible drag and drop page builder that works on the front end of your WordPress website. Whether you&#8217;re a beginner or a professional, you&#8217;re going to love taking control of your website. Stop writing HTML or wrestling with confusing shortcodes. With Beaver Builder, building beautiful, professional WordPress pages is as easy as dragging and dropping.</p> <p>Watch the video below or <a href="https://www.wpbeaverbuilder.com/go/demo?utm_medium=bb-lite&amp;utm_source=repo-readme&amp;utm_campaign=repo-demo-link" title="Beaver Builder Live Demo" rel="nofollow ugc">try out the demo</a> to see it in action!</p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/WUGyahZ5D2s?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <blockquote> <p><strong>Premium Support</strong></p> <p>The Beaver Builder team provides very limited support on the WordPress.org forums. Please feel free to post questions or bug reports, but for <em>timely</em> support, we recommend purchasing a Beaver Builder license.</p> <p>Along with access to our expert support team, there are many time-saving features in the premium versions which make it a great value for any serious WordPress user. <a href="https://www.wpbeaverbuilder.com/pricing/?utm_medium=bb-lite&amp;utm_source=repo-readme&amp;utm_campaign=repo-support-cta" title="Beaver Builder Premium Support" rel="nofollow ugc"><strong>Get a license today.</strong></a></p> <p>You can also reference our <a href="https://docs.wpbeaverbuilder.com/" title="Beaver Builder Knowledge Base" rel="nofollow ugc">Knowledge Base</a>, or try asking the Beaver Builder community for help in either <a href="http://beaver.builders/wp-repo-fb" title="Beaver Builders on Facebook" rel="nofollow ugc">Facebook</a> or <a href="https://www.wpbeaverbuilder.com/go/beaver-builders-slack" title="Beaver Builders on Slack" rel="nofollow ugc">Slack</a>. Keep in mind, these are all folks just like you who are volunteering their time.</p> </blockquote> <h4>Join our Growing Community</h4> <p>There is a huge colony (<em>yeah, that&#8217;s the term for a group of beavers</em>) of &#8220;Beaver Builders&#8221; that would love to get to know you! If you have questions, a project to show off, or you would like to meet and network with other Beaver Builder users, you&#8217;ll feel right at home in the <a href="http://beaver.builders/wp-repo-fb" title="Beaver Builders on Facebook" rel="nofollow ugc">Beaver Builders Facebook Group</a> or the <a href="https://www.wpbeaverbuilder.com/go/beaver-builders-slack" title="Beaver Builders on Slack" rel="nofollow ugc">Beaver Builders Slack Channel</a>. Come on by and say hello.</p> <h4>Page Builder Features</h4> <ul> <li>Content Modules: Box, Photo, Button, Button Group, Callout, Call to Action, Heading, Icon, Menu, Number Counter, Text Editor, HTML, Audio, Video, &amp; Sidebar.</li> <li>Full-width, column-based layouts.</li> <li>Create flexbox and CSS grid layouts with the Box Module. Also included are some Box module presets to get you going faster!</li> <li>Lightweight and semantic markup for maximum performance.</li> <li>Photo, color, and video row backgrounds.</li> <li>Mobile-friendly, responsive layouts.</li> <li>Add your own CSS classes and IDs.</li> <li>Use WordPress Widgets and shortcodes.</li> <li>Works with Pages, Posts, and Custom Post Types.</li> <li>A friendly and supportive community.</li> <li>Build your own custom modules.</li> </ul> <h4>Premium Features</h4> <ul> <li>Additional modules: Contact Form, Tabs, Slider, Pricing Table, Map, Blog Posts, Subscribe Form and many more.</li> <li>Beaver Themer Theme Builder.</li> <li>Beaver Builder Theme.</li> <li>Expert support from our world-class support team.</li> <li>Beautiful pre-made layout templates.</li> <li>Save, export, and reuse full-page layouts, rows, and modules.</li> <li>Save a Global Color palette.</li> <li>Create styles that apply globally throughout your Beaver Builder layouts.</li> </ul> <p>Come by <a href="https://www.wpbeaverbuilder.com/?utm_medium=bb-lite&amp;utm_source=repo-readme&amp;utm_campaign=repo-homepage-link" title="Beaver Builder Homepage" rel="nofollow ugc">the Beaver Builder Homepage</a> to learn more about what our premium features can do for you!</p> <h4>People REALLY LOVE Beaver Builder</h4> <p>Don&#8217;t just take our word for it, here are a few testimonials from happy users and customers.</p> <p>&#8220;Simply put, it is the best page builder in the WordPress ecosystem. There is no close second.&#8221; &#8211; WP Crafter</p> <p>&#8220;Complete design freedom with no coding and it is all fully responsive as well.&#8221; &#8211; skyboro</p> <p>&#8220;Easy to use, fast to get started, real product depth, great support.&#8221; &#8211; David Bressler</p> <h4>Modules And Widgets</h4> <p>We&#8217;ve loaded Beaver Builder up with a flexible set of content modules to aid you in building stunning layouts and landing pages within an intuitive drag and drop system. Beaver Builder also supports core and third party WordPress widgets and shortcodes, so you can use Beaver Builder with all your <em>other</em> favorite plugins!</p> <h4>A WordPress Page Builder That Works With Your Theme</h4> <p>Yep, that&#8217;s right! Beaver Builder was designed to work with almost any WordPress theme. Try Beaver Builder on your existing website today, or consider upgrading and using Beaver Builder&#8217;s outstanding framework theme (available in Pro and Agency packages) for your next project.</p> <h4>A WordPress Page Builder That&#8217;s 100% Mobile Friendly</h4> <p>Every part of a Beaver Builder layout or landing page is fully responsive and looks gorgeous on any screen size. Responsive web design has never been easier.</p> <h4>A WordPress Page Builder That&#8217;s Optimized For Performance</h4> <p>We&#8217;ve designed Beaver Builder to create layouts and landing pages that load quickly. Many page builders load in an ungodly number of scripts and stylesheets to every page on your site. Not Beaver Builder! It only loads the assets needed for a given layout or landing page.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
13.2M