← WordPress Vulnerabilities
WordPress security by component

Bold Page Builder

Bold Page Builder is a WordPress component with 35 published CVE records in this archive. The latest tracked vulnerability was published May 14, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: bold-page-builder

CVE-2026-3694: Bold Page Builder: Cross-site scripting

Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.6.8.

PublishedMay 14, 2026
Known safe version> 5.6.8
Safe version
May 14, 2026 CVE-2026-3694
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.6.8.
> 5.6.8
CVE6.4
NVDPending
Feb 19, 2026 CVE-2026-25451
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Feb 07, 2026 CVE-2025-15267
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Feb 07, 2026 CVE-2025-13463
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Feb 07, 2026 CVE-2025-12803
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Feb 07, 2026 CVE-2025-12159
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Nov 21, 2025 CVE-2025-66057
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Oct 23, 2025 CVE-2025-7730
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Aug 27, 2025 CVE-2025-58194
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jul 16, 2025 CVE-2025-54006
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
May 29, 2025 CVE-2025-5286
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
May 18, 2025 CVE-2025-3715
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
May 07, 2025 CVE-2025-47525
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
May 07, 2025 CVE-2025-47488
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Dec 16, 2024 CVE-2024-54382
Bold Page Builder: Filesystem traversal
Bold Page Builder is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVD4.9
Dec 06, 2024 CVE-2024-53801
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Nov 19, 2024 CVE-2024-50417
Bold Page Builder: A security weakness
Bold Page Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Oct 06, 2024 CVE-2024-47298
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Oct 05, 2024 CVE-2024-47391
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jul 30, 2024 CVE-2024-7100
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 10, 2024 CVE-2024-2736
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 10, 2024 CVE-2024-2735
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 10, 2024 CVE-2024-2734
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 10, 2024 CVE-2024-2733
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Apr 09, 2024 CVE-2024-3267
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-3266
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 29, 2024 CVE-2024-30442
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 27, 2024 CVE-2024-30179
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Feb 13, 2024 CVE-2024-1160
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Feb 13, 2024 CVE-2024-1159
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 13, 2024 CVE-2024-1157
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Dec 15, 2023 CVE-2023-49823
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jul 11, 2022 CVE-2022-2089
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Aug 30, 2021 CVE-2021-24579
bt_bb_get_grid AJAX action of the Bold Page Builder: Code execution
bt_bb_get_grid AJAX action of the Bold Page Builder is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVD8.8
Aug 30, 2019 CVE-2019-15821
Bold Page Builder: A security weakness
Bold Page Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5