Impact
The vulnerability in the Bold Page Builder plugin is a stored cross‑site scripting flaw located in the ‘percentage’ parameter of the progress bar component. Because the plugin does not properly sanitize or escape this input, an attacker who can create or edit content with Contributor or higher privileges can inject malicious JavaScript that is stored in the database and executed whenever an end‑user loads a page containing the affected element. This can lead to theft of session cookies, defacement or other client‑side attacks on users who view the page.
Affected Systems
WordPress sites utilizing the Bold Page Builder plugin from Bold Themes where the installed version is 5.4.5 or earlier. The vulnerability is present in all releases up to and including 5.4.5; later releases are untainted.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate‑severity flaw, and the EPSS score of less than 1% suggests current exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers must have authenticated Contributor-level or higher access, after which the stored payload runs for any user that visits the affected page. Given the limited attack surface but high impact on end‑users, administrators should act promptly to mitigate potential exposure.
OpenCVE Enrichment