Impact
An unauthenticated cross‑site scripting flaw exists in the Post and Page Builder by BoldGrid plugin, allowing an attacker to inject arbitrary JavaScript into the editor’s input handling. The vulnerability arises from unsanitized user input that is rendered in page content, enabling the execution of malicious scripts in the browsers of anyone who views the affected pages or posts. Potential consequences include session hijacking, defacement, or phishing attacks carried out within the victim’s authenticated session.
Affected Systems
BoldGrid’s Post and Page Builder by BoldGrid (Visual Drag and Drop Editor) WordPress plugin, versions up to and including 1.27.14. The vulnerability is fixed in version 1.27.15 and later, so only installations running 1.27.14 or earlier are impacted.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high probability of exploitation, though no EPSS data is currently available and the issue is not listed in CISA’s KEV catalog. Because the plugin is a WordPress component, the attack vector is likely local to the web application context, meaning any external user who can view the site’s content could potentially trigger the injection. Given the moderate to high risk rating and absence of mitigation controls, the vulnerability poses a significant threat to sites that rely on this plugin for content creation.
OpenCVE Enrichment