Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total20
Critical0
High1
Medium19
Reset
Showing 1-20 of 20 records
Threat Entry Updated 2026-02-09

CVE-2025-15267 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2025-15267

MEDIUM CVSS 6.4 2026-02-07
Threat Entry Updated 2026-02-09

CVE-2025-13463 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid component in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2025-13463

MEDIUM CVSS 6.4 2026-02-07
Threat Entry Updated 2026-02-09

CVE-2025-12803 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shortcode in all versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2025-12803

MEDIUM CVSS 6.4 2026-02-07
Threat Entry Updated 2026-02-09

CVE-2025-12159 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_raw_content shortcode in all versions up to, and including, 5.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2025-12159

MEDIUM CVSS 6.4 2026-02-07
Threat Entry Updated 2025-10-27

CVE-2025-7730 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter in all versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2025-7730

MEDIUM CVSS 6.4 2025-10-23
Threat Entry Updated 2025-07-03

CVE-2024-5647 - Bold Page Builder Plugin

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.

PLUGIN Bold Page Builder

CVE-2024-5647

MEDIUM CVSS 6.4 2025-07-03
Threat Entry Updated 2025-05-29

CVE-2025-5286 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ parameter in all versions up to, and including, 5.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2025-5286

MEDIUM CVSS 6.4 2025-05-29
Threat Entry Updated 2025-05-19

CVE-2025-3715 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2025-3715

MEDIUM CVSS 6.4 2025-05-18
Threat Entry Updated 2025-02-06

CVE-2024-7100 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-7100

MEDIUM CVSS 6.4 2024-07-30
Threat Entry Updated 2025-01-08

CVE-2024-2736 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tags in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-2736

MEDIUM CVSS 6.4 2024-04-10
Threat Entry Updated 2025-01-08

CVE-2024-2735 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Price List' element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-2735

MEDIUM CVSS 6.4 2024-04-10
Threat Entry Updated 2025-01-08

CVE-2024-2734 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AI features all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-2734

MEDIUM CVSS 6.4 2024-04-10
Threat Entry Updated 2025-01-08

CVE-2024-2733 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Separator" element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-2733

MEDIUM CVSS 5.4 2024-04-10
Threat Entry Updated 2025-01-08

CVE-2024-3267 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_list shortcode in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-3267

MEDIUM CVSS 6.4 2024-04-09
Threat Entry Updated 2025-01-08

CVE-2024-3266 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-3266

MEDIUM CVSS 6.4 2024-04-09
Threat Entry Updated 2024-11-21

CVE-2024-1159 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-1159

MEDIUM CVSS 6.4 2024-02-13
Threat Entry Updated 2024-11-21

CVE-2024-1160 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-1160

MEDIUM CVSS 5.4 2024-02-13
Threat Entry Updated 2024-11-21

CVE-2024-1157 - Bold Page Builder Plugin

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Bold Page Builder

CVE-2024-1157

MEDIUM CVSS 5.4 2024-02-13
Threat Entry Updated 2024-11-21

CVE-2022-2089 - Bold Page Builder Plugin

The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PLUGIN Bold Page Builder

CVE-2022-2089

MEDIUM CVSS 4.8 2022-07-11
Threat Entry Updated 2024-11-21

CVE-2021-24579 - Bold Page Builder Plugin

The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to fully exploit the issue, other installed plugins on the blog could allow such issue to be exploited and lead to RCE in some cases.

PLUGIN Bold Page Builder

CVE-2021-24579

HIGH CVSS 8.8 2021-08-30
Scroll to top