CVE-2026-18843 Overview
CVE-2026-18843 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Beaver Builder Plugin (Starter Version) for WordPress. The flaw resides in the no_results_message parameter of the node_preview functionality. All versions up to and including 2.11.0.1 fail to properly sanitize input and escape output, allowing unauthenticated attackers to inject arbitrary JavaScript. Exploitation requires user interaction, such as convincing a victim to click a crafted link. The issue is tracked under CWE-79.
Critical Impact
Unauthenticated attackers can execute arbitrary JavaScript in the browser context of any user who clicks a malicious link, enabling session theft, credential harvesting, and administrative account compromise.
Affected Products
- Beaver Builder Plugin (Starter Version) for WordPress, versions ≤ 2.11.0.1
- WordPress sites using the vulnerable node_preview handler
- Any deployment exposing the plugin's preview endpoints to unauthenticated visitors
Discovery Timeline
- 2026-09-05 - CVE-2026-18843 published to the National Vulnerability Database
- 2026-09-08 - Last updated in NVD database
Technical Details for CVE-2026-18843
Vulnerability Analysis
The vulnerability originates in the Beaver Builder plugin's node_preview request handler. The handler accepts a no_results_message parameter and reflects its value back into rendered HTML without sufficient sanitization or escaping. An unauthenticated attacker can craft a URL containing malicious JavaScript in this parameter. When a victim clicks the link, the payload executes in the victim's browser under the target site's origin.
The attack succeeds without authentication because the preview endpoint accepts crafted parameters from any visitor. The scope change to a different security context amplifies the impact, giving injected scripts access to sensitive DOM content and session state belonging to authenticated users who trigger the payload.
Root Cause
The root cause is insufficient input sanitization combined with improper output escaping in the no_results_message value handled by node_preview. User-controlled data is written into HTML output without contextual encoding, allowing script tags and event handlers to be rendered as executable content rather than inert text.
Attack Vector
Exploitation is network-based and requires user interaction. An attacker crafts a URL containing a JavaScript payload in the no_results_message parameter and delivers it via phishing email, malicious advertisement, social media, or an attacker-controlled page. When an authenticated administrator or editor clicks the link, the payload runs with their privileges. Attackers commonly abuse this to create rogue admin accounts, exfiltrate cookies, or inject persistent backdoors through the WordPress admin interface.
Refer to the Wordfence Vulnerability Report for technical details on the affected parameter and request path.
Detection Methods for CVE-2026-18843
Indicators of Compromise
- HTTP requests to Beaver Builder node_preview endpoints containing no_results_message parameters with <script>, onerror=, onload=, or javascript: substrings
- Unexpected WordPress administrator accounts, modified user roles, or new plugin installations following inbound clicks on external links
- Outbound requests from browsers to unfamiliar domains immediately after loading a Beaver Builder preview URL
Detection Strategies
- Inspect web server and WAF logs for requests to Beaver Builder preview endpoints containing URL-encoded HTML or JavaScript in no_results_message
- Deploy WAF rules that flag reflected parameters containing script tags, event handlers, or encoded angle brackets
- Correlate referrer headers pointing to external phishing infrastructure with subsequent admin-panel activity
Monitoring Recommendations
- Enable request logging on the wp-admin/admin-ajax.php and Beaver Builder REST routes
- Monitor WordPress user_meta and wp_users tables for unexpected changes to administrator accounts
- Alert on Content Security Policy (CSP) violation reports referencing inline script execution on pages that render Beaver Builder previews
How to Mitigate CVE-2026-18843
Immediate Actions Required
- Update the Beaver Builder Plugin (Starter Version) to the version released after 2.11.0.1 that addresses this issue
- Force a password reset for all administrator and editor accounts if suspicious activity is observed
- Audit installed plugins, themes, and user accounts for unauthorized modifications
Patch Information
Apply the vendor update from Beaver Builder that supersedes version 2.11.0.1. Consult the Wordfence Vulnerability Report for the specific fixed version and remediation guidance.
Workarounds
- Restrict access to Beaver Builder preview endpoints to authenticated users via web server or WAF rules until patching is complete
- Deploy a strict Content Security Policy that blocks inline script execution on pages served by the plugin
- Train administrators and content editors to avoid clicking untrusted links, especially those referencing WordPress preview URLs
# Example WAF rule (ModSecurity) to block script payloads in the vulnerable parameter
SecRule ARGS:no_results_message "@rx (?i)(<script|onerror=|onload=|javascript:)" \
"id:1026018843,phase:2,deny,status:403,log,msg:'CVE-2026-18843 Beaver Builder XSS attempt'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
