Sceawere
Vulnerability Detail
CVE-2026-6172UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Bold Page Builder Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- boldthemes
- Product
- Bold Page Builder
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-09-30T08:16:33.800Z",
"pubdate": "2026-09-30T08:16:33.800Z",
"executiveSummary": "The Bold Page Builder plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 5.7.2.\nThis security flaw stems from inadequate sanitization and output escaping of the 'caption' attribute within the 'bt_bb_image' shortcode.\nThe vulnerability allows authenticated users with Contributor-level privileges or higher to inject malicious JavaScript payloads into WordPress posts or pages.\nUpon a victim accessing the compromised page, the stored script executes within the context of the user's browser session.\nThe impact includes potential session hijacking, unauthorized actions performed on behalf of authenticated administrators, and the redirection of users to malicious external domains.\nGiven that this vulnerability requires authenticated access, it poses a significant risk for multi-author environments where lower-privileged users might attempt to escalate privileges or exfiltrate sensitive administrative session data.",
"technicalDetails": "The vulnerability originates from the improper handling of user-supplied input within the 'bt_bb_image' shortcode logic of the Bold Page Builder plugin.\nSpecifically, the 'caption' parameter fails to undergo rigorous server-side input sanitization or context-aware output encoding before being rendered in the Document Object Model (DOM).\nBecause the plugin processes these shortcodes during the rendering of page content, any arbitrary JavaScript payload embedded within the 'caption' attribute is persisted in the WordPress database.\nThe exploitation flow begins when an authenticated attacker (possessing at least Contributor-level access) creates or edits a post using the Bold Page Builder interface.\nThe attacker inserts a crafted 'bt_bb_image' shortcode, embedding an XSS payload within the 'caption' field (e.g., [bt_bb_image caption='<script>alert(document.cookie)</script>']).\nWhen the WordPress post is subsequently rendered, the server fails to neutralize the malicious tags, injecting the raw script into the HTML output.\nWhen an unsuspecting user, such as a site administrator, views the compromised page, the browser interprets the injected script as legitimate site content.\nThis execution happens within the security context of the victim's session, allowing the script to access cookies, local storage, and perform background requests to the WordPress REST API or other administrative endpoints.\nThis persistent nature of the injection ensures that the payload is executed each time the affected page is loaded, regardless of the attacker's ongoing session status.\nThe lack of output escaping is the primary failure point, as it violates the security principle of treating all user-supplied shortcode attributes as untrusted input that requires strict validation and sanitization before inclusion in the final HTML response sent to the client browser."
}