Impact
The vulnerability occurs in the Bold Page Builder WordPress plugin. An authenticated user with Contributor‑level access can insert malicious JavaScript into the 'images' attribute of the bt_bb_css_image_grid shortcode. Because the plugin does not properly escape or sanitize this input, the malicious payload is stored in the database. When a page containing the shortcode is loaded, the script runs in the browser of any visitor, which can lead to session hijacking, defacement, or other downstream attacks. This flaw is a classic stored cross‑site scripting condition described by CWE‑79.
Affected Systems
All instances running Bold Page Builder version 5.7.2 or earlier are affected, regardless of the underlying WordPress version. Any site that includes the bt_bb_css_image_grid shortcode in its content is at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to already have authenticated access with Contributor or higher privileges, but no external input is needed beyond using the shortcode. Once injected, the payload remains stored and will affect all subsequent visitors to the compromised page.
OpenCVE Enrichment