Impact
The vulnerability is a classic stored XSS flaw in the Bold Page Builder plugin, where user input is not properly sanitized before being rendered in the generated web page. An attacker who can inject scripts through an allowed content field can have those scripts executed in the browsers of any visitor who loads the affected page, potentially allowing session hijacking, defacement, or drive‑by download. The weakness falls under CWE‑79.
Affected Systems
WordPress sites that use the Bold Page Builder plugin from the boldthemes family, including any installation of versions 5.6.9 and earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates medium‑to‑high severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that an attacker have or gain permission to edit content through the plugin interface; once present, the malicious script is stored and served to all page viewers.
OpenCVE Enrichment