Beaver Builder WordPress Page Builder Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the Beaver Builder WordPress Page Builder plugin, affecting all versions through 2.9.4. The issue arises in the 'get_attachment_sizes' function, where authenticated attackers with Contributor-level access or higher can access private attachment data, including paths and metadata, potentially leading to unauthorized viewing of these attachments.

Impact

Exploitation of this vulnerability allows authenticated users with Contributor-level access and above to access sensitive information, specifically the paths and metadata of private attachments, which could be used to view those attachments.

Remediation

Users can update to Beaver Builder version 2.9.4.1 or a newer patched version to address this vulnerability.

Added: Dec 9, 2025, 8:56 PM
Updated: Dec 9, 2025, 8:56 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.9
remediation
7.7
relevance
1.4
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.