WordPress security by component
Bold Page Builder
Plugin description
Bold Page Builder is a WordPress component with 35 published CVE records in this archive. The latest tracked vulnerability was published May 14, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
bold-page-builderLatest vulnerability
CVE-2026-3694: Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.6.8.
| Safe version |
|
||
|---|---|---|---|
| May 14, 2026 |
CVE-2026-3694
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.6.8.
|
> 5.6.8 |
CVE6.4
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25451
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 07, 2026 |
CVE-2025-15267
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 07, 2026 |
CVE-2025-13463
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 07, 2026 |
CVE-2025-12803
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 07, 2026 |
CVE-2025-12159
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Nov 21, 2025 |
CVE-2025-66057
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 23, 2025 |
CVE-2025-7730
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Aug 27, 2025 |
CVE-2025-58194
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jul 16, 2025 |
CVE-2025-54006
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| May 29, 2025 |
CVE-2025-5286
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 18, 2025 |
CVE-2025-3715
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 07, 2025 |
CVE-2025-47525
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| May 07, 2025 |
CVE-2025-47488
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 16, 2024 |
CVE-2024-54382
Bold Page Builder: Filesystem traversal
Bold Page Builder is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Dec 06, 2024 |
CVE-2024-53801
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Nov 19, 2024 |
CVE-2024-50417
Bold Page Builder: A security weakness
Bold Page Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Oct 06, 2024 |
CVE-2024-47298
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Oct 05, 2024 |
CVE-2024-47391
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jul 30, 2024 |
CVE-2024-7100
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 10, 2024 |
CVE-2024-2736
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 10, 2024 |
CVE-2024-2735
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 10, 2024 |
CVE-2024-2734
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 10, 2024 |
CVE-2024-2733
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Apr 09, 2024 |
CVE-2024-3267
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 09, 2024 |
CVE-2024-3266
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 29, 2024 |
CVE-2024-30442
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 27, 2024 |
CVE-2024-30179
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Feb 13, 2024 |
CVE-2024-1160
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Feb 13, 2024 |
CVE-2024-1159
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 13, 2024 |
CVE-2024-1157
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Dec 15, 2023 |
CVE-2023-49823
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jul 11, 2022 |
CVE-2022-2089
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Aug 30, 2021 |
CVE-2021-24579
bt_bb_get_grid AJAX action of the Bold Page Builder: Code execution
bt_bb_get_grid AJAX action of the Bold Page Builder is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Aug 30, 2019 |
CVE-2019-15821
Bold Page Builder: A security weakness
Bold Page Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|