Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode Element Attributes
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.8epss 0.2%
exploitation probability
0.2%top 85% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Affected products
Unknown · Bold Page Builderpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/53bbe80c-caea-4893-82a6-03e5173390de/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.