The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Group module in all versions up to, and including, 2.8.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 49,574 live websites that are affected by CVE-2024-9049.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 49,574 live websites (35% of Beaver Builder install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 278 versions ( 90% of all versions) |
| 33,017 websites | |
| 2,070 websites | |
| 1,875 websites | |
| 1,564 websites | |
| 1,525 websites | |
| 1,034 websites | |
| 1,016 websites | |
| 872 websites | |
| 626 websites | |
| 606 websites |
| .com | 32,969 websites |
| .org | 3,174 websites |
| .co.uk | 1,447 websites |
| .net | 1,279 websites |
| .de | 1,167 websites |
| .ca | 961 websites |
| .com.au | 951 websites |
| .nl | 803 websites |
| .fr | 428 websites |
| .jp | 419 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.site | *,*** | ||
| *****.org | **,*** | ||
| *******.com | **,*** | ||
| ***.***.sg | **,*** | ||
| **********.com | **,*** | ||
| *********.com | **,*** | ||
| ********.com | **,*** | ||
| *******.com | **,*** | ||
| *****************.com | **,*** | ||
| ***********.com | **,*** |
FAQ