Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldThemes Bold Page Builder allows Path Traversal.This issue affects Bold Page Builder: from n/a through 5.1.5.
Fixes

Solution

Update the WordPress Bold Page Builder plugin to the latest available version (at least 5.1.6).


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00192}

epss

{'score': 0.00217}


Tue, 07 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Bold-themes
Bold-themes bold Page Builder
CPEs cpe:2.3:a:bold-themes:bold_page_builder:*:*:*:*:*:wordpress:*:*
Vendors & Products Bold-themes
Bold-themes bold Page Builder

Mon, 16 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldThemes Bold Page Builder allows Path Traversal.This issue affects Bold Page Builder: from n/a through 5.1.5.
Title WordPress Bold Page Builder plugin <= 5.1.5 - Path Traversal vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2024-12-16T19:42:50.961Z

Reserved: 2024-12-02T12:05:43.083Z

Link: CVE-2024-54382

cve-icon Vulnrichment

Updated: 2024-12-16T19:34:38.690Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-16T15:15:12.313

Modified: 2025-01-07T18:00:04.237

Link: CVE-2024-54382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.