Impact
The Bold Page Builder plugin contains an Improper Neutralization of Input During Web Page Generation flaw, allowing attacker‑supplied scripts to be stored and executed when a page is rendered. This stored XSS can be used to deface the site, steal user session cookies, run hidden prompts or inject malicious code into visitors’ browsers, leading to loss of confidentiality, integrity and possibly availability of the affected website.
Affected Systems
The vulnerability affects the Bold Page Builder plugin from boldthemes, specifically all releases up to and including version 5.3.0. Any WordPress installation that uses one of these versions is at risk.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity, while the EPSS score of less than 1% suggests exploitation is uncommon at present. It is not listed in the CISA KEV catalog. The attack vector is likely via the plugin’s content input interface, so an attacker who can add or edit content will be able to inject malicious scripts that are subsequently displayed to anyone viewing the affected page. The vulnerability is not considered critical, but its impact on user sessions justifies timely mitigation.
OpenCVE Enrichment
EUVD