WordPress security by component
Bold Page Builder
Plugin description
Bold Page Builder provides a visual drag-and-drop editor for creating and arranging WordPress page content and layouts.
Bold Page Builder (bold-page-builder) is a WordPress plugin with 40 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
bold-page-builderLatest vulnerability
CVE-2026-62110: Bold Page Builder permits contributor cross-site scripting
Bold Page Builder through 5.9.9 permits cross-site scripting by an authenticated Contributor. The CNA vector requires another user to interact with the affected content and rates confidentiality, integrity, and availability impacts as low. The authoritative export does not identify the endpoint, action, parameter, storage path, rendering function, or output context.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62110
Bold Page Builder permits contributor cross-site scripting
Bold Page Builder through 5.9.9 permits cross-site scripting by an authenticated Contributor. The CNA vector requires another user to interact with the affected content and rates confidentiality, integrity, and availability impacts as low. The authoritative export does not identify the endpoint, action, parameter, storage path, rendering function, or output context.
|
5.9.10 |
CVE6.5
NVDPending
|
| Sep 06, 2026 |
CVE-2026-84028
Bold Page Builder permits Contributor-level stored XSS
Bold Page Builder before 5.9.9 outputs a Contributor-controlled shortcode attribute into an HTML attribute without adequate sanitization and escaping. A Contributor or higher can store script that executes when another user views the affected page.
|
5.9.9 |
CVE6.8
NVDPending
|
| Sep 05, 2026 |
CVE-2026-84022
Bold Page Builder permits Contributor-level stored XSS through shortcode attributes
Bold Page Builder before 5.9.8 outputs several Contributor-controlled shortcode attributes into HTML attributes without adequate sanitization and escaping. A Contributor or higher can store script that executes when another user views the affected page.
|
5.9.8 |
CVE6.8
NVDPending
|
| Sep 05, 2026 |
CVE-2026-84021
Bold Page Builder permits Contributor-level link-triggered stored XSS
Bold Page Builder before 5.9.8 relies on a bypassable URL filter before placing a Contributor-controlled link into an HTML attribute. A Contributor or higher can store script that executes when a visitor clicks the affected link.
|
5.9.8 |
CVE6.8
NVDPending
|
| Aug 16, 2026 |
CVE-2026-2357
Bold Page Builder shortcode attributes permit Contributor stored XSS
Bold Page Builder through 5.6.8 fails to sanitize and contextually escape attacker-controlled attributes of the bt_bb_shortcode shortcode. A Contributor can store an attribute-breaking script payload in post content, and the script executes when any visitor, including an administrator, views the rendered page. The public.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 14, 2026 |
CVE-2026-3694
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.6.8.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25451
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 07, 2026 |
CVE-2025-15267
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 07, 2026 |
CVE-2025-13463
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 07, 2026 |
CVE-2025-12803
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 07, 2026 |
CVE-2025-12159
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Nov 21, 2025 |
CVE-2025-66057
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 23, 2025 |
CVE-2025-7730
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Aug 27, 2025 |
CVE-2025-58194
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jul 16, 2025 |
CVE-2025-54006
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| May 29, 2025 |
CVE-2025-5286
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 18, 2025 |
CVE-2025-3715
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 07, 2025 |
CVE-2025-47525
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| May 07, 2025 |
CVE-2025-47488
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 16, 2024 |
CVE-2024-54382
Bold Page Builder: Filesystem traversal
Bold Page Builder is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Dec 06, 2024 |
CVE-2024-53801
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Nov 19, 2024 |
CVE-2024-50417
Bold Page Builder: A security weakness
Bold Page Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Oct 06, 2024 |
CVE-2024-47298
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Oct 05, 2024 |
CVE-2024-47391
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jul 30, 2024 |
CVE-2024-7100
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 10, 2024 |
CVE-2024-2736
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 10, 2024 |
CVE-2024-2735
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 10, 2024 |
CVE-2024-2734
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 10, 2024 |
CVE-2024-2733
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Apr 09, 2024 |
CVE-2024-3267
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 09, 2024 |
CVE-2024-3266
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 29, 2024 |
CVE-2024-30442
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 27, 2024 |
CVE-2024-30179
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Feb 13, 2024 |
CVE-2024-1160
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Feb 13, 2024 |
CVE-2024-1159
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 13, 2024 |
CVE-2024-1157
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Dec 15, 2023 |
CVE-2023-49823
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jul 11, 2022 |
CVE-2022-2089
Bold Page Builder: Cross-site scripting
Bold Page Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Aug 30, 2021 |
CVE-2021-24579
bt_bb_get_grid AJAX action of the Bold Page Builder: Code execution
bt_bb_get_grid AJAX action of the Bold Page Builder is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Aug 30, 2019 |
CVE-2019-15821
Bold Page Builder: A security weakness
Bold Page Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|