CVE-2026-95865 Beaver Builder 插件盲 SQL 注入漏洞
影响具有 Contributor 及以上权限的攻击者可注入 SQL 语句,窃取数据库敏感信息
WordPress 的 Beaver Builder Page Builder 插件在 2.11.0.5 及之前所有版本中存在盲 SQL 注入漏洞。漏洞位于 get_autosuggest_values AJAX 接口,因对 fields[][value] 参数转义不足且 SQL 查询未做充分预处理,攻击者可向已有查询中追加恶意 SQL 语句。
影响范围
Beaver Builder Page Builder 插件所有版本至 2.11.0.5(含)。
漏洞详情
漏洞类型为盲 SQL 注入,成因是插件对用户传入的 fields[][value] 参数未进行充分转义,且构造 SQL 查询时未使用预处理语句。任何拥有草稿文章所有权的 Contributor 均可访问存在漏洞的 get_autosuggest_values AJAX 端点,因为 fl_ajax_update nonce 会向所有可编辑 Beaver Builder 文章类型的用户下发。攻击者借此可向现有查询追加 SQL 语句,从数据库中提取敏感信息。
利用条件与风险
利用需具备 Contributor 及以上权限并拥有草稿文章,属于认证后攻击,实战中可用于窃取数据库中的敏感数据。
修复建议
建议升级至官方修复版本;暂无公开信息说明具体修复版本号,临时缓解措施为限制 Contributor 权限或禁用相关 AJAX 接口。
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via ‘fields[][value]’ Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable get_autosuggest_values AJAX endpoint is reachable by any Contributor who owns a draft post, as the required fl_ajax_update nonce is emitted into the block editor for any user who can edit a Beaver Builder post type.