What is CVE-2026-17090?
CVE-2026-17090 is a Stored Cross-Site Scripting (XSS) vulnerability in the Beaver Builder plugin for WordPress, affecting versions up to and including 2.10.2.2. The flaw exists in the Button Module's 'button' (Button Code) setting due to insufficient input sanitization and output escaping. Users should update the plugin to the latest patched version immediately.
Azərbaycanca: CVE-2026-17090 WordPress üçün Beaver Builder plaginində aşkar edilmiş Stored Cross-Site Scripting (XSS) zəifliyidir. Bu zəiflik Button modulunun 'button' (Button Code) parametrində kifayət qədər input sanitization və output escaping olmaması səbəbindən 2.10.2.2 və daha əvvəlki versiyalara təsir edir. İstifadəçilər plagini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Beaver Builder plugin are affected by CVE-2026-17090?
This vulnerability affects Beaver Builder plugin versions up to and including 2.10.2.2.
What is the root cause of CVE-2026-17090?
The vulnerability is caused by insufficient input sanitization and output escaping in the Button Module's 'button' (Button Code) setting.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.