THREAT OPS › Threat News › [NVD] CVE-2026-18843 (MEDIUM 6.1) — The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes i
[NVD] CVE-2026-18843 (MEDIUM 6.1) — The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes i
CVE-2026-18843 CVSS: 6.1 MEDIUM Published: 2026-09-05T07:17:11.207
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a
Indicators of compromise
- CVE-2026-18843cve
- 2.11.0.1ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18843