Sceawere
Vulnerability Detail
CVE-2026-6170UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Bold Page Builder Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- boldthemes
- Product
- Bold Page Builder
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-09-30T08:16:33.513Z",
"pubdate": "2026-09-30T08:16:33.513Z",
"executiveSummary": "The Bold Page Builder plugin for WordPress, in versions up to and including 5.7.2, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability resides within the bt_bb_css_image_grid shortcode, specifically involving the 'images' parameter.\nThe flaw stems from insufficient input sanitization and inadequate output escaping of user-supplied data. An authenticated attacker possessing Contributor-level privileges or higher can inject malicious JavaScript payloads into the plugin's configuration.\nWhen a victim, such as an administrator or another user, accesses a page containing the compromised shortcode, the injected script executes within the context of the user's browser session. This allows for unauthorized actions, potential session hijacking, or the defacement of site content.\nGiven that WordPress contributors can create and save content, this vulnerability represents a significant risk to site integrity and security. Successful exploitation does not require advanced network access, relying instead on the legitimate permissions already granted to the attacker account.",
"technicalDetails": "The vulnerability is identified as a Stored Cross-Site Scripting (XSS) flaw located within the Bold Page Builder plugin. The primary component affected is the bt_bb_css_image_grid shortcode, which processes an 'images' attribute intended to render dynamic image galleries. The root cause of the vulnerability is the absence of rigorous server-side input validation and client-side output encoding when handling user-provided data passed through this specific shortcode parameter.\nExploitation is feasible for any authenticated user with a role of Contributor or higher. These users have the capability to create posts and insert shortcodes. An attacker can craft a malicious shortcode implementation by injecting a payload into the 'images' attribute. For example, by inserting an HTML tag containing an 'onload' or 'onerror' event handler, such as '<img src=x onerror=alert(document.cookie)>', the attacker embeds malicious code directly into the WordPress database.\nThe attack flow follows these steps: First, the attacker creates or edits a WordPress post, injecting the crafted malicious shortcode containing a JavaScript payload into the 'images' parameter. Second, the plugin processes this shortcode during the rendering phase, failing to neutralize the dangerous script tags or event handlers. Third, the unsanitized payload is persisted in the WordPress database. Finally, when a target user—potentially an administrator or a visitor—views the affected page, the WordPress CMS renders the shortcode. The browser interprets the injected JavaScript and executes it within the victim's security context.\nBecause the payload is stored on the server, the impact is persistent. The execution occurs every time the page is loaded by any user, not just the attacker. This can lead to the exfiltration of session cookies, redirection of users to malicious third-party websites, or unauthorized requests performed on behalf of the victim (Cross-Site Request Forgery). The vulnerability highlights a failure in the plugin’s development lifecycle to properly sanitize user inputs against common injection vectors, particularly when those inputs are eventually reflected in the DOM (Document Object Model) without proper context-aware escaping."
}