Fastlinemedia develops WordPress plugins and themes, including Beaver Builder, Beaver Themer, and related customization and assistant tools, that extend page-building and content-management capabilities for site administrators and designers. The vulnerability profile concentrates in these web-application plugins and reflects the recurring challenges of client-side customization workflows: cross-site scripting through improper input neutralization during page generation, insecure deserialization of untrusted data, and authorization and file-upload control gaps that arise when plugins extend WordPress's flexibility to third parties. While the vendor's disclosure volume is modest relative to the broader ecosystem, the products occupy a prominent position in the WordPress builder market and present a meaningful attack surface for both plugin administrators and end-user site visitors. Defenders should treat updates to these plugins as a routine priority within WordPress hardening and pay particular attention to file-upload and data-import functionality given the recurring patterns; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fastlinemedia over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1347HIGH The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Ob | May 8, 2023 | 7.2 | 30 | NO | NO |
CVE-2022-36425CRITICAL Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress. | Sep 6, 2022 | 9.8 | 29 | NO | NO |
CVE-2023-5798HIGH The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_get(), which could allow users with a role as low as Editor to | Oct 26, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-3380HIGH The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (inte | Oct 31, 2022 | 7.2 | 24 | NO | NO |
CVE-2025-8897MEDIUM The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'fl_builder' parameter in all versions up to, and includin | Aug 28, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-8427MEDIUM The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 2. | Oct 23, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-4102HIGH The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_enabled_icons' function in | Jun 20, 2025 | 7.2 | 21 | NO | NO |
CVE-2024-1080MEDIUM The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via the heading tag in all versions up to, and including, 2.7. | Mar 13, 2024 | 5.4 | 21 | NO | NO |
CVE-2024-7620MEDIUM The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions up to, and i | Sep 7, 2024 | 6.6 | 20 | NO | NO |
CVE-2023-6695MEDIUM The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible | Apr 9, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fastlinemedia.
Media articles that mention a CVE ID that affects a product developed by Fastlinemedia — matched by CVE ID, not by vendor name.