Impact
The vulnerability arises because Bold Page Builder versions before 5.9.8 do not properly validate a link URL that is placed in an HTML attribute. This oversight allows users with the Contributor role and higher to supply arbitrary web scripts that execute when any site visitor clicks the affected link, resulting in a stored cross‑site scripting (XSS) flaw. The impact is full script execution in the context of the site’s users, enabling phishing, cookie theft, or further compromise of site content. The weakness is classified as an input validation failure that can be exploited through the web interface.
Affected Systems
Bold Page Builder plugin for WordPress, version 5.9.7 and earlier. Users who have the Contributor role or greater within a WordPress site that has an affected installation are at risk. The vulnerability does not affect other WordPress core components or plugins directly.
Risk and Exploitability
Because the flaw is stored and does not require user interaction beyond clicking a link, it is highly valuable to an attacker. The exploit requires only that the attacker can insert a link via the plugin’s editor, which can be achieved by any Contributor or higher. No VPN or network access is required. While an EPSS score is not available and the flaw is not listed in the CISA KEV catalog, the combination of wide role exposure and stored payloads suggests a high likelihood of exploitation once the vulnerability is discovered.
OpenCVE Enrichment