Impact
The vulnerability is a contributor‑based Cross Site Scripting flaw in Bold Page Builder versions 5.9.9 and earlier. An attacker who can submit content through the contributor interface can inject malicious JavaScript that executes when other users view the stored content. This can lead to cookie theft or arbitrary code execution in the victim’s browser, compromising confidentiality and integrity.
Affected Systems
WordPress sites using Bold Page Builder versions 5.9.9 or earlier are affected. The product is distributed by Bold Themes and specifically targets the Bold Page Builder plugin. Any installation lacking an upgrade to 5.9.10 or later remains vulnerable.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate exploitability and impact. The EPSS score is currently < 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation to date. The likely attack vector is an attacker with contributor access who can inject scripts that will run for all users viewing the compromised page. The impact is scoped to any visitor who engages with the page, validation mitigates the risk.
OpenCVE Enrichment