← WordPress Vulnerabilities
WordPress security by component

Post and Page Builder by BoldGrid

Post and Page Builder by BoldGrid is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Jan 06, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: post-and-page-builder

CVE-2025-69345: Post and Page Builder by BoldGrid: A security weakness

Post and Page Builder by BoldGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJan 06, 2026
Safe version guidanceSee mitigation notes
Safe version
Jan 06, 2026 CVE-2025-69345
Post and Page Builder by BoldGrid: A security weakness
Post and Page Builder by BoldGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Aug 14, 2025 CVE-2025-52712
Post and Page Builder by BoldGrid: Filesystem traversal
Post and Page Builder by BoldGrid is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.2
NVDPending
Jun 20, 2025 CVE-2025-52713
Post and Page Builder by BoldGrid: Server-side request forgery
Post and Page Builder by BoldGrid is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE6.4
NVDPending
Jun 20, 2025 CVE-2025-52711
Post and Page Builder by BoldGrid: Cross-site request forgery
Post and Page Builder by BoldGrid is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Feb 06, 2025 CVE-2025-0859
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: Filesystem traversal
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVDPending
Jul 20, 2024 CVE-2024-6848
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: Cross-site scripting
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 16, 2024 CVE-2024-4400
Post And Page Builder: Cross-site scripting
Post And Page Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 26, 2024 CVE-2024-2888
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: Cross-site scripting
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Oct 06, 2023 CVE-2023-25480
Post And Page Builder: Cross-site request forgery
Post And Page Builder is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8