Impact
The Bold Page Builder WordPress plugin contains a stored cross‑site scripting flaw affecting all versions up to and including 5.6.8. The plugin's bt_bb_shortcode shortcode does not properly sanitize or escape user‑supplied attributes, enabling an attacker with contributor‑level or higher privileges to inject arbitrary JavaScript that will execute whenever a page containing the shortcode is viewed by any user. Because the payload is stored in the database, it persists across visits and can be used for phishing, defacement, or session hijacking, thereby compromising the confidentiality and integrity of site visitors.
Affected Systems
Bold Page Builder versions 5.6.8 and earlier from BoldThemes, installed on WordPress sites.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. While the EPSS score is not available, the vulnerability requires authenticated access, so it is only exploitable by users with contributor or higher privileges. The flaw is not yet listed in the CISA KEV catalog, suggesting no confirmed active exploitation, but the stored nature of the XSS means any compromised contributor can deploy persistent, site‑wide scripts.
OpenCVE Enrichment