Description
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
Published: 2026-09-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side code execution via Cross Site Scripting
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated cross‑site scripting flaw exists in the Post and Page Builder by BoldGrid plugin, allowing an attacker to inject arbitrary JavaScript into the editor’s input handling. The vulnerability arises from unsanitized user input that is rendered in page content, enabling the execution of malicious scripts in the browsers of anyone who views the affected pages or posts. Potential consequences include session hijacking, defacement, or phishing attacks carried out within the victim’s authenticated session.

Affected Systems

BoldGrid’s Post and Page Builder by BoldGrid (Visual Drag and Drop Editor) WordPress plugin, versions up to and including 1.27.14. The vulnerability is fixed in version 1.27.15 and later, so only installations running 1.27.14 or earlier are impacted.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high probability of exploitation, though no EPSS data is currently available and the issue is not listed in CISA’s KEV catalog. Because the plugin is a WordPress component, the attack vector is likely local to the web application context, meaning any external user who can view the site’s content could potentially trigger the injection. Given the moderate to high risk rating and absence of mitigation controls, the vulnerability poses a significant threat to sites that rely on this plugin for content creation.

Generated by OpenCVE AI on September 30, 2026 at 18:46 UTC.

Remediation

Vendor Solution

Update the WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin to the latest available version (at least 1.27.15).


OpenCVE Recommended Actions

  • Update the WordPress Post and Page Builder by BoldGrid plugin to version 1.27.15 or later.
  • If an update is not immediately available, temporarily disable or remove the plugin to eliminate the vulnerable code path.
  • Review and delete any existing malicious or suspicious scripts that may have already been injected into posts or pages.

Generated by OpenCVE AI on September 30, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Boldgrid
Boldgrid post And Page Builder
Wordpress-extensions
Wordpress-extensions post And Page Builder By Boldgrid
Vendors & Products Boldgrid
Boldgrid post And Page Builder
Wordpress-extensions
Wordpress-extensions post And Page Builder By Boldgrid

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
Title WordPress Post and Page Builder by BoldGrid plugin <= 1.27.14 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Boldgrid Post And Page Builder
Wordpress-extensions Post And Page Builder By Boldgrid
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T17:59:55.497Z

Reserved: 2026-09-26T00:17:50.215Z

Link: CVE-2026-100510

cve-icon Vulnrichment

Updated: 2026-09-30T17:59:20.955Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:17:59.147

Modified: 2026-09-30T19:04:41.917

Link: CVE-2026-100510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:35:48Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')