Stored Cross-Site Scripting Vulnerability in Bold Timeline Lite Plugin for WordPress
CVE-2026-7438
6.4MEDIUM
What is CVE-2026-7438?
The Bold Timeline Lite plugin for WordPress contains a vulnerability that allows authenticated users with Contributor-level access and above to exploit the supertitle and subtitle attributes in the bold_timeline_item shortcode. Due to insufficient input sanitization and output escaping, attackers can inject arbitrary web scripts into pages. This malicious script will execute whenever a user accesses the compromised page, posing significant risks to site security and user data integrity.
Affected Version(s)
Bold Timeline Lite 0 <= 1.2.8