Sceawere

Vulnerability Detail

CVE-2026-6172UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Bold Page Builder Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
boldthemes
Product
Bold Page Builder
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-09-30T08:16:33.800Z",
  "pubdate": "2026-09-30T08:16:33.800Z",
  "executiveSummary": "The Bold Page Builder plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 5.7.2.\nThis security flaw stems from inadequate sanitization and output escaping of the 'caption' attribute within the 'bt_bb_image' shortcode.\nThe vulnerability allows authenticated users with Contributor-level privileges or higher to inject malicious JavaScript payloads into WordPress posts or pages.\nUpon a victim accessing the compromised page, the stored script executes within the context of the user's browser session.\nThe impact includes potential session hijacking, unauthorized actions performed on behalf of authenticated administrators, and the redirection of users to malicious external domains.\nGiven that this vulnerability requires authenticated access, it poses a significant risk for multi-author environments where lower-privileged users might attempt to escalate privileges or exfiltrate sensitive administrative session data.",
  "technicalDetails": "The vulnerability originates from the improper handling of user-supplied input within the 'bt_bb_image' shortcode logic of the Bold Page Builder plugin.\nSpecifically, the 'caption' parameter fails to undergo rigorous server-side input sanitization or context-aware output encoding before being rendered in the Document Object Model (DOM).\nBecause the plugin processes these shortcodes during the rendering of page content, any arbitrary JavaScript payload embedded within the 'caption' attribute is persisted in the WordPress database.\nThe exploitation flow begins when an authenticated attacker (possessing at least Contributor-level access) creates or edits a post using the Bold Page Builder interface.\nThe attacker inserts a crafted 'bt_bb_image' shortcode, embedding an XSS payload within the 'caption' field (e.g., [bt_bb_image caption='<script>alert(document.cookie)</script>']).\nWhen the WordPress post is subsequently rendered, the server fails to neutralize the malicious tags, injecting the raw script into the HTML output.\nWhen an unsuspecting user, such as a site administrator, views the compromised page, the browser interprets the injected script as legitimate site content.\nThis execution happens within the security context of the victim's session, allowing the script to access cookies, local storage, and perform background requests to the WordPress REST API or other administrative endpoints.\nThis persistent nature of the injection ensures that the payload is executed each time the affected page is loaded, regardless of the attacker's ongoing session status.\nThe lack of output escaping is the primary failure point, as it violates the security principle of treating all user-supplied shortcode attributes as untrusted input that requires strict validation and sanitization before inclusion in the final HTML response sent to the client browser."
}
CVE-2026-6172: Bold Page Builder Stored XSS (MEDIUM Severity, CVSS: 6.4) | Sceawere