Stored Cross-Site Scripting in Bold Page Builder Plugin for WordPress
CVE-2026-6170
6.4MEDIUM
What is CVE-2026-6170?
The Bold Page Builder plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping. This vulnerability resides in the 'images' parameter of the bt_bb_css_image_grid shortcode, affecting all versions up to and including 5.7.2. Authenticated attackers with Contributor-level access can exploit this flaw to inject malicious scripts into pages, which subsequently execute upon a user's visit to the affected page.
Affected Version(s)
Bold Page Builder 0 <= 5.7.2