Impact
The Bold Page Builder plugin for WordPress contains a stored cross‑site scripting flaw in its bt_bb_accordion_item shortcode. All releases up to and including 5.6.1 accept user‑supplied attributes without proper sanitization or output escaping, allowing authenticated contributors or higher to embed arbitrary JavaScript payloads into post content. When a visitor loads the affected page, the injected script runs in their browser, enabling session hijacking, defacement, or other malicious effects.
Affected Systems
WordPress sites that use the Bold Page Builder plugin by boldthemes, versions up to and including 5.6.1, are affected. Any installation of the plugin within that version range that utilizes the bt_bb_accordion_item shortcode is vulnerable. The flaw is independent of site configuration and is exploitable when the shortcode is used.
Risk and Exploitability
With a CVSS score of 6.4 the risk is moderate, and an EPSS score of less than 1 % indicates that exploitation is unlikely under current conditions. The vulnerability is explicitly not listed in the CISA KEV catalog. Attackers must be authenticated with contributor‑level access or higher; the exploit requires site login and access to the shortcode insertion interface. Once a script is injected, it executes for all page visitors, potentially compromising session data or enabling defacement, but widespread exploitation is constrained by the authentication requirement.
OpenCVE Enrichment