Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesBold Page Builder

Bold Page Builder vulnerabilities

Bold Page Builder has 32 known vulnerabilities in this database. The most recent published record is dated 30 Sep 2026.

Known vulnerabilities
32
Active installs
40,000+
Latest version
5.9.10
Last updated
9 Sep 2026
Most recent
30 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-88037
Medium 6.4Up to 5.7.2Fixed in a later version (latest 5.9.10)7 d ago
Cross-site scripting (XSS)
CVE-2026-6170
Medium 6.4Up to 5.7.2Fixed in a later version (latest 5.9.10)7 d ago
Cross-site scripting (XSS)
CVE-2026-6171
Medium 6.4Up to 5.7.2Fixed in a later version (latest 5.9.10)7 d ago
Cross-site scripting (XSS)
CVE-2026-6172
Medium 6.4Up to 5.7.2Fixed in a later version (latest 5.9.10)7 d ago
Cross-site scripting (XSS)
CVE-2026-6173
Medium 6.4Up to 5.7.2Fixed in a later version (latest 5.9.10)7 d ago
Cross-site scripting (XSS)
CVE-2026-5920
Medium 6.4Up to 5.9.6Fixed in a later version (latest 5.9.10)16 Sep 2026
Cross-site scripting (XSS)
CVE-2026-84028
Medium 6.8Before 5.9.9Fixed in 5.9.96 Sep 2026
Cross-site scripting (XSS)
CVE-2026-84021
Medium 6.8Before 5.9.8Fixed in 5.9.85 Sep 2026
Cross-site scripting (XSS)
CVE-2026-84022
Medium 6.8Before 5.9.8Fixed in 5.9.85 Sep 2026
Cross-site scripting (XSS)
CVE-2026-2357
Medium 6.4Up to 5.6.8Fixed in a later version (latest 5.9.10)16 Aug 2026
Cross-site scripting (XSS)
CVE-2026-3694
Medium 6.4Up to 5.6.8Fixed in a later version (latest 5.9.10)14 May 2026
Cross-site scripting (XSS)
CVE-2025-12803
Medium 6.4Up to 5.5.1Fixed in a later version (latest 5.9.10)7 Feb 2026
Cross-site scripting (XSS)
CVE-2025-13463
Medium 6.4Up to 5.5.3Fixed in a later version (latest 5.9.10)7 Feb 2026
Cross-site scripting (XSS)
CVE-2025-15267
Medium 6.4Up to 5.6.1Fixed in a later version (latest 5.9.10)7 Feb 2026
Cross-site scripting (XSS)
CVE-2025-12159
Medium 6.4Up to 5.4.8Fixed in a later version (latest 5.9.10)7 Feb 2026
Cross-site scripting (XSS)
CVE-2025-7730
Medium 6.4Up to 5.4.5Fixed in a later version (latest 5.9.10)23 Oct 2025
Cross-site scripting (XSS)
CVE-2024-5647
Medium 6.4Not yet publishedCheck for an update3 Jul 2025
Cross-site scripting (XSS)
CVE-2025-5286
Medium 6.4Up to 5.3.6Fixed in a later version (latest 5.9.10)29 May 2025
Cross-site scripting (XSS)
CVE-2025-3715
Medium 6.4Up to 5.3.5Fixed in a later version (latest 5.9.10)18 May 2025
Cross-site scripting (XSS)
CVE-2024-7100
Medium 6.4Before 5.0.3Fixed in 5.0.330 Jul 2024
Cross-site scripting (XSS)
CVE-2024-2734
Medium 6.4Before 4.8.9Fixed in 4.8.910 Apr 2024
Cross-site scripting (XSS)
CVE-2024-2735
Medium 6.4Before 4.8.9Fixed in 4.8.910 Apr 2024
Cross-site scripting (XSS)
CVE-2024-2736
Medium 6.4Before 4.8.9Fixed in 4.8.910 Apr 2024
Cross-site scripting (XSS)
CVE-2024-2733
Medium 5.4Before 4.8.9Fixed in 4.8.910 Apr 2024
Cross-site scripting (XSS)
CVE-2024-3266
Medium 6.4Before 4.8.9Fixed in 4.8.99 Apr 2024
Cross-site scripting (XSS)
CVE-2024-3267
Medium 6.4Before 4.8.9Fixed in 4.8.99 Apr 2024
Cross-site scripting (XSS)
CVE-2024-1157
Medium 5.4Before 4.8.1Fixed in 4.8.113 Feb 2024
Cross-site scripting (XSS)
CVE-2024-1159
Medium 6.4Before 4.8.1Fixed in 4.8.113 Feb 2024
Cross-site scripting (XSS)
CVE-2024-1160
Medium 5.4Before 4.8.1Fixed in 4.8.113 Feb 2024
Cross-site scripting (XSS)
CVE-2022-2089
Medium 4.8Before 4.3.3Fixed in 4.3.311 Jul 2022
Remote code execution
CVE-2021-24579
High 8.8Before 3.1.6Fixed in 3.1.630 Aug 2021
Security weakness
CVE-2019-15821
High 7.5Before 2.3.2Fixed in 2.3.230 Aug 2019
Read the published descriptions
CVE-2026-88037, 30 Sep 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-6170, 30 Sep 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-6171, 30 Sep 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-6172, 30 Sep 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-6173, 30 Sep 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-5920, 16 Sep 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6. This is due to a bypassable security filter (bt_bb_save_pre) that can be circumvented via null byte injection, combined with insufficient output sanitization of base64-decoded content in the bt_bb_raw_content shortcode handler. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-84028, 6 Sep 2026
The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page. CVE record
CVE-2026-84021, 5 Sep 2026
The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link. CVE record
CVE-2026-84022, 5 Sep 2026
The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page. CVE record
CVE-2026-2357, 16 Aug 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, 5.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-3694, 14 May 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the bt_bb_button shortcode in all versions up to, and including, 5.6.8. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-12803, 7 Feb 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shortcode in all versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-13463, 7 Feb 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid component in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-15267, 7 Feb 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-12159, 7 Feb 2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_raw_content shortcode in all versions up to, and including, 5.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-7730, 23 Oct 2025
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter in all versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-5647, 3 Jul 2025
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default. CVE record
CVE-2025-5286, 29 May 2025
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ parameter in all versions up to, and including, 5.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-3715, 18 May 2025
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-7100, 30 Jul 2024
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2734, 10 Apr 2024
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AI features all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2735, 10 Apr 2024
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Price List' element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2736, 10 Apr 2024
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tags in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2733, 10 Apr 2024
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Separator" element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-3266, 9 Apr 2024
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-3267, 9 Apr 2024
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_list shortcode in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-1157, 13 Feb 2024
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-1159, 13 Feb 2024
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-1160, 13 Feb 2024
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-30442 is likely a duplicate of this issue. CVE record
CVE-2022-2089, 11 Jul 2022
The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. CVE record
CVE-2021-24579, 30 Aug 2021
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to fully exploit the issue, other installed plugins on the blog could allow such issue to be exploited and lead to RCE in some cases. CVE record
CVE-2019-15821, 30 Aug 2019
The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data. CVE record

What to do if you run Bold Page Builder

If you run Bold Page Builder, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Bold Page Builder vulnerabilities

Free. We email you when a new vulnerability is published for Bold Page Builder, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support