Stored Cross-Site Scripting Vulnerability in Bold Page Builder Plugin for WordPress
CVE-2026-6173

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 September 2026

What is CVE-2026-6173?

The Bold Page Builder plugin for WordPress contains a vulnerability that could allow authenticated attackers, with Contributor-level access and above, to exploit the 'background_image' parameter of the plugin's bt_bb_section shortcode. This issue arises from inadequate input sanitization and output escaping for user-supplied attributes, enabling the injection of arbitrary web scripts. When users access pages with these scripts, they may unintentionally execute harmful code, potentially compromising their data and security.

Affected Version(s)

Bold Page Builder 0 <= 5.7.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucas torres (Rooting)
.