Impact
The vulnerability resides in the Bold Page Builder WordPress plugin prior to version 5.9.8, where several shortcode attributes are output directly into HTML attributes without proper sanitisation or escaping. This omission permits any user with the Contributor role or higher to inject arbitrary JavaScript code that executes when the associated page is viewed by others. The impact is a stored cross‑site scripting attack, enabling attackers to perform phishing, defacement, or cookie theft from unsuspecting site visitors.
Affected Systems
Affected systems are WordPress sites that have the Bold Page Builder plugin installed at any version lower than 5.9.8. The plugin is identified by the vendor name Bold Page Builder, and the CVE notes that any contributor or higher role can exploit the flaw. Specific version numbers are not listed beyond the <5.9.8 threshold, so all installations preceding that release are considered vulnerable.
Risk and Exploitability
No CVSS score is reported in the available data, and the EPSS score is unavailable, indicating that usage statistics are unknown. Because the exploit requires a web context and an authenticated contributor, the attack vector is likely via normal site editing or page creation by a role with contributor privileges. The flaw is listed as not in CISA KEV, so there is no current known exploitation campaign, but the stored XSS remains a high‑impact vulnerability that could undermine site integrity and user trust.
OpenCVE Enrichment