Sceawere
Vulnerability Detail
CVE-2026-6173UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Bold Page Builder Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- boldthemes
- Product
- Bold Page Builder
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-09-30T08:16:33.940Z",
"pubdate": "2026-09-30T08:16:33.940Z",
"executiveSummary": "The Bold Page Builder plugin for WordPress, in versions up to and including 5.7.2, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from improper input sanitization and output escaping mechanisms within the 'background_image' parameter of the 'bt_bb_section' shortcode.\nThe vulnerability enables an authenticated attacker with at least Contributor-level privileges to inject malicious JavaScript payloads directly into the WordPress database. When a victim, such as an administrator or a standard site visitor, views a page containing the compromised shortcode, the injected script executes within the context of the user's browser session.\nThis vulnerability poses a significant risk to site integrity and user security. Successful exploitation allows for unauthorized actions, including the potential theft of session cookies, redirection to malicious domains, or unauthorized administrative modifications. Because the payload is persistent and stored in the database, the attack does not require ongoing interaction from the threat actor after the initial injection. This flaw highlights the critical necessity for robust input validation and context-aware output encoding in WordPress plugin development.",
"technicalDetails": "The root cause of this vulnerability is the failure of the Bold Page Builder plugin to adequately sanitize user-supplied attributes before processing them within the 'bt_bb_section' shortcode. Specifically, the 'background_image' parameter is passed directly to the rendering engine without applying necessary security filters or sanitization functions.\nThe attack flow begins when an authenticated user with Contributor privileges (or higher) creates or edits a page using the Bold Page Builder. The attacker inserts the 'bt_bb_section' shortcode and modifies the 'background_image' attribute to contain a crafted payload, such as 'javascript:alert(document.domain)'. Because the plugin fails to validate this attribute, the malicious string is successfully saved into the WordPress post_content table.\nUpon subsequent rendering of the page, the plugin retrieves the stored shortcode data. The component responsible for processing 'bt_bb_section' outputs the content of the 'background_image' parameter directly into the generated HTML markup without appropriate escaping, such as esc_attr() or esc_url(). This allows the browser to interpret the injected data as executable code rather than a static string. If a victim visits the affected page, the malicious payload executes within their browser session.\nThis Stored XSS attack is particularly dangerous because it bypasses standard security expectations for input handling. An attacker can leverage this primitive to perform various post-exploitation activities, such as capturing sensitive authentication tokens, modifying DOM elements to facilitate phishing attacks, or executing background requests to the WordPress API if the victim possesses higher-level administrative credentials. Since the payload is stored persistently, any user who accesses the compromised page will trigger the script, potentially leading to mass compromise of administrative accounts if the page is viewed by privileged users.\nThe vulnerability affects all versions of Bold Page Builder up to 5.7.2. It requires an authenticated session, but the low barrier for entry (Contributor access) makes it a viable attack vector for unauthorized users who have successfully gained initial access to the WordPress environment."
}