The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_enabled_icons' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability was partially patched in version 2.9.1.
We have discovered 91,521 live websites that are affected by CVE-2025-4102.
| Product | |
| Category | Wordpress Themes |
| Vulnerable Domains | 91,521 live websites (100% of Beaver Builder install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 65 versions ( 100% of all versions) |
| 62,374 websites | |
| 5,493 websites | |
| 3,510 websites | |
| 3,413 websites | |
| 2,777 websites | |
| 2,304 websites | |
| 2,073 websites | |
| 1,006 websites | |
| 710 websites | |
| 646 websites |
| .com | 56,622 websites |
| .org | 8,232 websites |
| .co.uk | 3,868 websites |
| .nl | 3,197 websites |
| .net | 2,259 websites |
| .de | 2,121 websites |
| .com.au | 1,963 websites |
| .ca | 1,673 websites |
| .fr | 1,113 websites |
| .ch | 814 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | *,*** | ||
| ********.com | *,*** | ||
| ********.com | *,*** | ||
| ***************.com | *,*** | ||
| ***********************.com | *,*** | ||
| ***.***.au | *,*** | ||
| ***.edu | *,*** | ||
| ***.org | *,*** | ||
| ***********************.com | **,*** | ||
| *********.com | **,*** |
FAQ