Impact
The vulnerability lies in the 'caption' attribute of the bt_bb_image shortcode. Input from users is not properly escaped during output, allowing an attacker to embed malicious JavaScript. This flaw, classified as CWE‑79, permits an authenticated user with Contributor or higher privileges to inject scripts that run in the browsers of anyone who views the affected page. The result is session hijacking, credential theft, defacement, or other malicious activity without needing to exploit any external attack surface.
Affected Systems
This flaw affects the Bold Page Builder plugin for WordPress, versions 5.7.2 and earlier. Users running these versions need to identify whether their site uses the bt_bb_image component and whether Contributor or higher users can add or edit images via the shortcode.
Risk and Exploitability
The CVSS base score of 6.4 indicates a moderate severity. No EPSS score is published, so the likelihood of exploitation in the wild cannot be quantified from the available data. The vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation at this time. Attackers must be authenticated and have Contributor or higher role permissions to exploit the flaw.
OpenCVE Enrichment