Impact
The vulnerability allows an authenticated contributor or higher to supply malicious JavaScript in the title attribute of the bt_bb_service shortcode. The plugin fails to sanitize or escape the value, so the script is stored in the database and executed whenever a page containing the shortcode is viewed. This can deface the site, steal credentials, or perform other malicious actions within the context of the site.
Affected Systems
WordPress sites that use the Bold Page Builder plugin from boldthemes, including all releases up to and including version 5.7.2. Any user with contributor‑level or higher privileges can exploit the flaw.
Risk and Exploitability
With a CVSS score of 6.4 the vulnerability is considered moderate. The EPSS score is not available, and the flaw has not yet been listed in CISA’s KEV catalog, indicating no known public exploits. The attack vector requires that an attacker have contributor‑level access to a WordPress site, so the risk is driven primarily by the internal privilege model of the site. If a contributor account is compromised or an attacker gains such access, the stored XSS can execute in the browsers of all users who view the affected page.
OpenCVE Enrichment