Sceawere
Vulnerability Detail
CVE-2026-6171UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Bold Page Builder Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- boldthemes
- Product
- Bold Page Builder
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-09-30T08:16:33.657Z",
"pubdate": "2026-09-30T08:16:33.657Z",
"executiveSummary": "The Bold Page Builder plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability residing within the bt_bb_icon shortcode functionality.\nThe vulnerability originates from inadequate input sanitization and output escaping mechanisms applied to the 'target' parameter when processing shortcode attributes.\nThe security flaw allows authenticated users with Contributor-level privileges or higher to inject malicious JavaScript payloads into post or page content.\nWhen a victim, such as an administrator or another site visitor, views the affected content, the injected script executes within the context of the user's browser session.\nThis vulnerability poses a significant risk to the integrity and security of the WordPress installation, potentially enabling session hijacking, unauthorized administrative actions, and the redirection of users to malicious domains.\nExploitation is limited to authenticated attackers, meaning the attack vector is contained within the internal user base of the WordPress site; however, it remains a critical concern for multi-user environments where contributor-level access is granted to untrusted parties.",
"technicalDetails": "The vulnerability is identified within the Bold Page Builder plugin, specifically affecting versions up to and including 5.7.2. The flaw exists due to a failure in the plugin's shortcode processing logic, where the 'target' attribute of the 'bt_bb_icon' shortcode is treated as trusted input.\nDuring the rendering phase, the plugin fails to sanitize user-supplied data or properly encode the output before injecting it into the DOM. By crafting a specifically engineered 'bt_bb_icon' shortcode, an attacker can escape the intended HTML attribute context and inject arbitrary JavaScript.\nThe attack flow begins when an attacker with at least Contributor-level permissions adds the malicious shortcode to a page or post. The payload is stored in the WordPress database as part of the post content. Once the page is saved and subsequently published or viewed by an authorized user, the server-side processing of the shortcode renders the malicious script directly into the HTML response.\nBecause the payload is stored persistently in the database, the script executes every time the affected page is loaded. This allows for persistent execution of malicious code within the context of the victim's authenticated session.\nThe impact of successful exploitation is broad. An attacker could execute arbitrary JavaScript to perform actions on behalf of the victim, including but not limited to: stealing session cookies, modifying site content, creating new administrative users, or executing asynchronous requests to the WordPress REST API to perform unauthorized configuration changes.\nThe lack of output escaping for the 'target' attribute means that even if basic input filtering is present, an attacker can bypass it using various encoding techniques to inject event handlers (e.g., 'onmouseover') or URI schemes (e.g., 'javascript:alert(1)') depending on where the attribute is placed within the HTML tag attributes. This flaw highlights a critical architectural failure in handling shortcode attributes, where user-defined parameters are directly reflected in the DOM without secondary validation or output encoding filters."
}