Impact
The Bold Page Builder plugin for WordPress contains a stored cross‑site scripting vulnerability that can be triggered by the "target" attribute of the bt_bb_icon shortcode. User‑supplied input is neither sanitized nor properly escaped, allowing an authenticated user with Contributor access or higher to embed JavaScript that will be executed automatically on every subsequent visitor to the affected page. This flaw is a classic example of CWE‑79 input validation weakness.
Affected Systems
All installations of the Bold Page Builder plugin for WordPress with versions 5.7.2 or earlier are impacted. The vulnerability resides in the plugin’s shortcode handling code and does not affect the core WordPress installation itself.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating moderate severity. No EPSS estimate is available, so the exploitation probability is unknown, but the flaw is listed as not in the CISA KEV catalog. The attacker must first obtain Contributor or higher role access and then insert malicious code through the icon shortcode; the code is stored and will be served to any user who views the page. If an attacker succeeds, they can deface the site, steal user data, or facilitate further attacks.
OpenCVE Enrichment