Impact
The vulnerability arises because the Bold Page Builder plugin fails to sanitise and escape a shortcode attribute before it is output in an HTML attribute. This flaw allows any user with a Contributor role or higher to inject arbitrary JavaScript that is stored within the plugin’s slider elements “additional_settings”. When a victim user views the affected page, the malicious script executes in the victim’s browser, enabling cookie theft, session hijacking, defacement, or other client‑side attacks. The impact is a client‑side compromise that can affect the confidentiality, integrity, and availability of user sessions.
Affected Systems
The affected product is the Bold Page Builder WordPress plugin, versions earlier than 5.9.9. The vendor is listed only as Unknown:Bold Page Builder, indicating that the plugin is available from the WordPress plugin repository but its maintainer is not explicitly identified in this record. All installations of the plugin prior to the 5.9.9 release are affected.
Risk and Exploitability
The flaw is a classic case of stored cross‑site scripting, which typically carries a high severity rating. Although no EPSS score is provided, the lack of a CISA KEV listing and the absence of a publicly known exploit do not reduce the theoretical risk; any user with Contributor privileges can maliciously craft the payload. Exploitation requires no additional conditions beyond ability to edit slider settings, so the risk is readily exploitable for authenticated users with sufficient role permissions. The unescaped user input is rendered in all browsers that view the page, making the attack vector client‑side and straightforward for an attacker with the required role.
OpenCVE Enrichment