Impact
Bold Page Builder, a WordPress plugin from Bold Themes, contains a stored cross‑site scripting flaw that can be exploited by users with Contributor or higher access. By injecting crafted data into the 'shortcode_content' parameter of the bt_bb_shortcode shortcode, an attacker can bypass a security filter and embed arbitrary scripts that are decoded from base64 and rendered. When a user views the page containing the malicious shortcode, the embedded script is executed in the victim’s browser and may steal session cookies, credentials, or perform other client‑side attacks. The weakness is a classic stored XSS problem, identified as CWE‑79.
Affected Systems
Bold Page Builder plugin for WordPress revisions up to and including version 5.9.6 are affected. Users of any of these vulnerable releases are at risk while running the plugin. Versions newer than 5.9.6 are not known to contain the flaw.
Risk and Exploitability
The flaw carries a CVSS score of 6.4, indicating moderate severity. Its EPSS score is less than 1%, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated with at least Contributor privileges to create or edit content that includes the vulnerable shortcode. Once injected, the malicious script executes for every subsequent visitor to that page, potentially scaling impact beyond the initial contributor.
OpenCVE Enrichment