Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fastlinemedia

First CVE: Jan 10, 2022Active for: 5 yearsTotal CVEs: 38
19.1
VTI Score
Low

Fastlinemedia develops WordPress plugins and themes, including Beaver Builder, Beaver Themer, and related customization and assistant tools, that extend page-building and content-management capabilities for site administrators and designers. The vulnerability profile concentrates in these web-application plugins and reflects the recurring challenges of client-side customization workflows: cross-site scripting through improper input neutralization during page generation, insecure deserialization of untrusted data, and authorization and file-upload control gaps that arise when plugins extend WordPress's flexibility to third parties. While the vendor's disclosure volume is modest relative to the broader ecosystem, the products occupy a prominent position in the WordPress builder market and present a meaningful attack surface for both plugin administrators and end-user site visitors. Defenders should treat updates to these plugins as a routine priority within WordPress hardening and pay particular attention to file-upload and data-import functionality given the recurring patterns; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
38
Total CVEs
More Total CVEs than 98% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fastlinemedia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2022
4 years ago
Most Recent CVE
Dec 9, 2025
227 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1347HIGH
The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Ob
May 8, 20237.230NONO
CVE-2022-36425CRITICAL
Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress.
Sep 6, 20229.829NONO
CVE-2023-5798HIGH
The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_get(), which could allow users with a role as low as Editor to
Oct 26, 20238.824NONO
CVE-2022-3380HIGH
The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (inte
Oct 31, 20227.224NONO
CVE-2025-8897MEDIUM
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'fl_builder' parameter in all versions up to, and includin
Aug 28, 20256.122NONO
CVE-2025-8427MEDIUM
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 2.
Oct 23, 20255.421NONO
CVE-2025-4102HIGH
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_enabled_icons' function in
Jun 20, 20257.221NONO
CVE-2024-1080MEDIUM
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via the heading tag in all versions up to, and including, 2.7.
Mar 13, 20245.421NONO
CVE-2024-7620MEDIUM
The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions up to, and i
Sep 7, 20246.620NONO
CVE-2023-6695MEDIUM
The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible
Apr 9, 20246.520NONO
View all 38 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products38 CVEs
87%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network38 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (97.4%)
High1 (2.6%)
Unknown0 (0.0%)
User Interaction
None12 (31.6%)
Unknown0 (0.0%)
Required26 (68.4%)
Privileges Required
Low27 (71.1%)
High5 (13.2%)
None6 (15.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fastlinemedia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fastlinemedia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fastlinemedia's Products

View all 4 CNAs →

Top CWEs