Stored Cross-Site Scripting in Bold Page Builder Plugin for WordPress
CVE-2026-6171
6.4MEDIUM
What is CVE-2026-6171?
The Bold Page Builder plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting (XSS) through the 'target' parameter of the bt_bb_icon shortcode. Due to inadequate sanitization of user-supplied input, authenticated users with Contributor-level access and higher can inject malicious web scripts into pages. These scripts execute when a user visits the affected page, potentially compromising site security and user data.
Affected Version(s)
Bold Page Builder 0 <= 5.7.2