Stored Cross-Site Scripting Vulnerability in Bold Page Builder Plugin for WordPress
CVE-2026-88037
6.4MEDIUM
What is CVE-2026-88037?
The Bold Page Builder plugin for WordPress contains a vulnerability that allows authenticated users with Contributor permissions and higher to exploit stored Cross-Site Scripting (XSS) flaws. This vulnerability arises from inadequate input sanitization and output escaping for the title attribute of the bt_bb_service shortcode. Attackers can inject arbitrary web scripts into pages, leading to potential malicious exploitation whenever an unsuspecting user accesses the compromised content.
Affected Version(s)
Bold Page Builder 0 <= 5.7.2