Impact
The vulnerability arises from insufficient sanitization of user‑supplied attributes in the bt_bb_accordion_item shortcode, allowing an attacker with contributor or higher privileges to embed arbitrary scripts into a page. These scripts are stored and executed for any visitor who views the affected page, providing a persistent cross‑site scripting vector.
Affected Systems
WordPress sites using the Bold Page Builder plugin by boldthemes, versions 5.5.7 and earlier are affected. Any installation of the plugin in that version range, regardless of configuration, is susceptible if the shortcode is used.
Risk and Exploitability
With a CVSS score of 6.4 the risk is moderate, and an EPSS score of less than 1% indicates that exploitation is unlikely under current conditions. The vulnerability is explicitly not listed in the CISA KEV catalog. Attackers must be authenticated with contributor‑level access or higher; the exploit requires site login and access to the shortcode insertion interface. Once a script is injected, it executes for all page visitors, potentially compromising session data or enabling defacement, but widespread exploitation is constrained by the authentication requirement.
OpenCVE Enrichment