Impact
The storage of the background_image attribute in the bt_bb_section shortcode of Bold Page Builder allows an authenticated user with contributor or higher privileges to input arbitrary JavaScript. The plugin fails to perform adequate sanitization and escaping when this attribute is saved, meaning the malicious code is persisted in the database and will be served to any visitor who views the affected page, leading to client‑side script execution.
Affected Systems
WordPress sites that have installed Bold Page Builder version 5.7.2 or earlier and include at least one user with contributor or higher role are impacted. Any content editor capable of adding or editing a section can exploit the flaw.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting no confirmed public exploits yet. The attack requires only that the attacker be authenticated and possess contributor‑level or higher permissions to create or modify a section; once the malicious code is stored, it will execute for every visitor of the page.
OpenCVE Enrichment