Beaver Builder & LatePoint: Unauthenticated Shortcode Execution Fixes
Contents
TL;DR
What happened Unauthenticated shortcode execution in Beaver Builder and LatePoint, plus unauthenticated SQL injection in Iptanus File Upload. Attackers need no WordPress login credentials.
What to do Update Beaver Builder to 2.11.0.6, LatePoint to 5.7.1 (5.7.3 includes subsequent security fixes), and Iptanus File Upload to 5.2.0 or later.
Severity Rated Critical (CVSS 9.1 to 9.3) by Wordfence and Patchstack, though execution requires specific modules, widgets, or form displays on the site.
Vulnerabilities that attackers can exploit without logging into WordPress have been disclosed for Beaver Builder, LatePoint, and Iptanus File Upload. These flaws appeared in WordPress vulnerability tracking on October 3, 2026. Patched versions are available for all three plugins, and successful exploitation depends on specific public-facing screens and configuration options.
Three Critical Vulnerabilities and Patched Versions
The table below is compiled from threat intelligence published by Wordfence and Patchstack. CVE identifiers track specific vulnerabilities, while CVSS scores evaluate exploitability and potential impact. All three issues were evaluated as Critical by reporting sources.
| Plugin | CVE & Reporter | CVSS | Affected Versions | Patched In |
|---|---|---|---|---|
| Beaver Builder | CVE-2026-92084 | 9.1 | <= 2.11.0.5 | 2.11.0.6 |
| LatePoint | CVE-2026-92966 | 9.1 | <= 5.7.0 | 5.7.1 |
| Iptanus File Upload | CVE-2026-62071 | 9.3 | <= 5.1.10 | 5.2.0 |
The fixed versions shown are the initial releases addressing each specific CVE.
For LatePoint, subsequent security fixes are also included in 5.7.3.
Execution of Shortcodes Embedded in Comments or Names
WordPress shortcodes use bracketed markup like [gallery] to invoke functions registered by core or plugins, rendering the results inline. The do_shortcode() function parses input strings and processes any detected shortcode tags.
In Beaver Builder, the flaw manifests when widgets inside the Sidebar module output text submitted by external users. Widgets are standard UI blocks that display components like comment streams.
Wordfence cites the Recent Comments widget as an example. If comment moderation is disabled or if a comment containing shortcode syntax is approved, the embedded shortcode executes when rendered on the page. Details: CVE-2026-92084 advisory.
LatePoint stores customer names submitted through its public booking form and renders them inside the Customer Cabinet block.
Because LatePoint passes this output through do_shortcode(), shortcode syntax entered during appointment booking is executed. Submitting the payload requires no WordPress administrator or author account. Details: CVE-2026-92966 advisory.
flowchart TD
A[Unauthenticated user inputs booking form] --> B[Shortcode injected into name field]
B --> C[Stored in database as customer name]
C --> D[Customer Cabinet displays name]
D --> E[do_shortcode executes injected string]
The capabilities exposed through this vector depend on which shortcodes are registered on the target site.
Under the hood, do_shortcode() calls handler functions matching registered tag names. While this is distinct from arbitrary PHP code execution, it triggers server-side routines from input originally intended solely for plain-text display.
Unauthenticated SQL Injection in Iptanus File Upload
Iptanus File Upload is a file submission plugin previously named WordPress File Upload.
According to Patchstack’s advisory, versions 5.1.10 and earlier contain an unauthenticated SQL injection vulnerability, patched in version 5.2.0.
SQL injection occurs when user-supplied input is concatenated into database commands rather than treated purely as parameter data.
The official CVE record rates the confidentiality impact as High. The developer’s 5.2.0 changelog explicitly notes fixes for SQL injection involving insufficiently sanitized upload identifiers.
Reviewing Configurations for W3 Total Cache and All in One SEO
Recent advisories for W3 Total Cache, All in One SEO, EWWW Image Optimizer, and WP Statistics also describe flaws exploitable without attacker credentials. Conditions for exploitation vary widely, such as displaying specific widgets on search pages or inducing a privileged user to follow a link. All in One SEO has two separate CVEs, separated into distinct rows below.
Cross-site scripting (XSS) in the table refers to vulnerabilities where attacker-supplied scripts execute inside a visiting user’s browser.
Stored XSS persists inside database fields like comments, whereas reflected XSS requires tricking a victim into clicking a crafted URL.
| Plugin | CVE & Reporter | Vector & Exploitation Conditions | Patched In |
|---|---|---|---|
| W3 Total Cache | CVE-2026-87920 | Stored XSS via comment content when the option to remove query strings from static resources is enabled | 2.10.7 |
| All in One SEO | CVE-2026-100152 | Shortcode execution via search query parameter s when All in One SEO breadcrumbs are displayed on search result pages | 5.0.2.1 |
| All in One SEO | CVE-2026-85492 | XSS via URL pathname requiring a user with SEO manager permissions to visit a crafted link and view the admin bar SEO Preview | 5.0.2 |
| EWWW Image Optimizer | CVE-2026-92826 | Reflected XSS requiring enable_help to be active and social engineering to guide a user to click a crafted link | 8.8.0 |
| WP Statistics | CVE-2026-97652 | Reflected XSS via URL query string requiring user interaction to follow a malicious link | 14.16.15 |
W3 Total Cache includes a setting titled “Remove query strings from static resources” that strips ? parameters from static asset URLs. In Wordfence’s advisory, the rewriting logic inadvertently stripped enclosing quotation marks, allowing attacker strings to break out of HTML attributes and trigger XSS. The 2.10.7 changelog confirms the URL rewriting fix.
All in One SEO breadcrumbs provide contextual hierarchical navigation. When active on search result pages, shortcodes supplied via the s search parameter are evaluated.
Version 5.0.2 resolved the URL pathname XSS (CVE-2026-85492), but the shortcode execution issue (CVE-2026-100152) persisted until version 5.0.2.1.
Gaps Between Patch Release and Advisory Disclosure
Dates on vulnerability trackers reflect disclosure timing rather than the day attacks began in the wild.
Aggregators pull from public vulnerability registries, typically listing plugins with over 10,000 installs, elevated exploitation probabilities, or confirmed active exploits. When a plugin receives multiple CVEs, each is tracked as a separate entry.
In LatePoint and EWWW Image Optimizer, patched versions were released in September 2026, while official CVE records appeared in October. The CVE publication dates below are shown in Japan Standard Time (JST).
| Plugin | Patch Release Date | CVE Record Publication Date |
|---|---|---|
| LatePoint | 5.7.1 on September 22, 2026 | CVE-2026-92966 on October 1, 2026 |
| EWWW Image Optimizer | 8.8.0 on September 24, 2026 | CVE-2026-92826 on October 3, 2026 |
A broader concentration of disclosures on specific dates cannot be explained from these two instances alone. Trackers count individual vulnerability records, not the number of breached sites or active attack campaigns.
EPSS scores displayed alongside vulnerability entries are the estimated probability that a known CVE will be exploited in the wild within the next 30 days (FIRST EPSS documentation).
This metric does not directly measure whether an individual site is compromised or whether updating can be safely skipped. Check installed plugin versions in the WordPress admin panel and apply updates containing the required fixes.