CVE-2025-4102

Beaver Builder Plugin (Starter Version) <= 2.9.1 - Authenticated (Administrator+) Arbitrary File Upload

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_enabled_icons' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability was partially patched in version 2.9.1.


We have discovered 91,521 live websites that are affected by CVE-2025-4102.

Run a Free Instant Scan




Affected Software

Product  Beaver Builder
Category Wordpress Themes
Vulnerable Domains91,521 live websites (100% of Beaver Builder install base)
Vulnerable Versions
  • from 0 through 2.9.1
Vulnerable Versions Count65 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Jun 20, 2025
  • Updated - Jun 20, 2025

Credits

  • Tom Broucke (finder)

Website Distribution by Country

Number of websites using CVE-2025-4102
United States62,374 websites



GB5,493 websites
Germany3,510 websites
Netherlands3,413 websites
Canada2,777 websites
France2,304 websites
Australia2,073 websites
Switzerland1,006 websites
South Africa710 websites
Norway646 websites

Website Distribution by TLD

Number of websites using CVE-2025-4102
.com56,622 websites
.org8,232 websites
.co.uk3,868 websites
.nl3,197 websites
.net2,259 websites
.de2,121 websites
.com.au1,963 websites
.ca1,673 websites
.fr1,113 websites
.ch814 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-4102

Top websites that are affected by CVE-2025-4102. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***
********.com United States*,***
********.com United States*,***
***************.com United States*,***
***********************.com United States*,***
***.***.au United States*,***
***.edu United States*,***
***.org United States*,***
***********************.com United States**,***
*********.com United States**,***
See full domain list

FAQ

CVE-2025-4102 is Unrestricted Upload of File with Dangerous Type in Beaver Builder
A total of 91,521 websites have been identified as vulnerable to CVE-2025-4102, based on global website indexing conducted by WebTechSurvey.
The Beaver Builder is affected by the CVE-2025-4102 vulnerability.
Beaver Builder versions up to and including 2.9.1 are vulnerable to CVE-2025-4102.