Description
The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-09-11
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the Bold Timeline Lite plugin for WordPress, allowing injected scripts to be stored in the "supertitle" and "subtitle" attributes of the bold_timeline_item shortcode. Contributors or higher‑privileged users can input arbitrary code through these fields, and the plugin fails to sanitize or escape the values before rendering them on the page. When a page containing the compromised shortcode is visited, the embedded JavaScript runs in the victim’s browser, enabling attackers to deface content, steal session cookies, or perform other client‑side attacks.

Affected Systems

WordPress sites using the Bold Timeline Lite plugin with versions 1.2.8 or earlier are affected. The issue arises when the plugin processes user‑supplied attributes for the bold_timeline_item shortcode through the WordPress content editing interface.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited widespread exploitation. The attack requires authenticated access with at least Contributor privileges, and the malicious script is stored and executed only when users view the affected page. The risk is primarily to site administrators and site visitors who trigger the injected code, and the impact is confined to client‑side execution rather than server‑side compromise.

Generated by OpenCVE AI on September 11, 2026 at 05:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Bold Timeline Lite to a version newer than 1.2.8, which implements proper sanitization and escaping of shortcode attributes.
  • If an immediate update is not possible, temporarily deactivate the plugin or remove editor roles that allow contributors to insert shortcodes, ensuring no further injections can occur.
  • Review existing content pages that use the bold_timeline_item shortcode, sanitize any user‑supplied titles and subtitles, and regenerate the pages so that malicious scripts are eliminated.
  • Consider adding a web‑application‑firewall rule to block script injection via the bold_timeline_item shortcode attributes to provide an additional protection layer.

Generated by OpenCVE AI on September 11, 2026 at 05:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Bold-themes
Bold-themes bold Timeline Lite
Wordpress
Wordpress wordpress
Vendors & Products Bold-themes
Bold-themes bold Timeline Lite
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Bold Timeline Lite <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Bold-themes Bold Timeline Lite
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T13:46:23.403Z

Reserved: 2026-04-29T15:43:27.737Z

Link: CVE-2026-7438

cve-icon Vulnrichment

Updated: 2026-09-11T13:38:55.336Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:55.657

Modified: 2026-09-11T14:17:34.480

Link: CVE-2026-7438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T17:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')