Summary
A Stored XSS vulnerability in the WordPress Beaver Builder plugin could let attackers inject scripts into websites. The flaw, due to insufficient input sanitization and output escaping, is more dangerous than a Reflected XSS. It's a medium threat, requiring contributor-level permissions to exploit. A patch is available in version 2.8.0.7 of the plugin.