Cross-site Scripting Vulnerability in Bold Page Builder by BoldThemes
CVE-2025-47525

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 May 2025

What is CVE-2025-47525?

Bold Page Builder by BoldThemes is susceptible to a Cross-site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. This can lead to stored XSS, where the injected scripts are executed in the browsers of users who visit the compromised pages. The issue affects all versions of Bold Page Builder from n/a through 5.3.0, making it crucial for users to upgrade to the latest version to safeguard against potential exploits.

Affected Version(s)

Bold Page Builder <= 5.3.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.