Sceawere
Vulnerability Detail
CVE-2026-88037UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Bold Page Builder Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- boldthemes
- Product
- Bold Page Builder
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-09-30T08:16:34.277Z",
"pubdate": "2026-09-30T08:16:34.277Z",
"executiveSummary": "The Bold Page Builder plugin for WordPress, in versions up to and including 5.7.2, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis flaw arises from inadequate input sanitization and output escaping mechanisms applied to the 'title' attribute within the 'bt_bb_service' shortcode.\nAn authenticated attacker with at least Contributor-level privileges can successfully inject malicious JavaScript payloads into post or page content.\nThe injected scripts are executed in the browser context of any user, including administrators, who views the compromised page.\nThe primary risk involves unauthorized execution of arbitrary scripts, potentially leading to session hijacking, unauthorized administrative actions, or defacement.\nExploitation requires authenticated access to the WordPress environment, which serves as a significant barrier for external unauthenticated actors but poses a substantial risk from malicious or compromised internal accounts.",
"technicalDetails": "The root cause of this vulnerability is the failure of the 'bt_bb_service' shortcode handler to sanitize user-supplied input for the 'title' attribute before storing it in the database, combined with a lack of proper context-aware output escaping when rendering the data on the front-end.\nIn the WordPress ecosystem, shortcode attributes are frequently parsed and rendered using functions that may default to insecure handling if developers do not explicitly implement sanitization filters, such as 'sanitize_text_field', or escaping functions, such as 'esc_attr' or 'esc_html'.\nAn attacker with Contributor-level permissions—who is permitted to create or edit posts—can insert the 'bt_bb_service' shortcode into the post editor. By manipulating the 'title' attribute to contain malicious payloads (e.g., 'title=\"<script>alert(document.cookie)</script>\"'), the attacker forces the application to persist this payload in the WordPress database.\nWhen a victim, such as a site administrator, loads the page containing the malicious shortcode, the server renders the stored 'title' attribute directly into the HTML source code of the page without encoding special characters. This leads to the browser interpreting the injected script tag as executable code rather than plain text.\nThe execution flow involves: 1) The attacker injects the malicious string via the shortcode interface; 2) The plugin backend saves the unsanitized input; 3) The frontend renders the raw output; 4) The victim's browser parses the malicious payload, triggering execution within the security context of the site origin.\nBecause the payload executes within the victim's session, the attacker can leverage the victim's authentication cookies or administrative privileges to perform unauthorized tasks, such as modifying site settings, creating new administrative accounts, or redirecting traffic to malicious domains.\nThe attack is limited to users with sufficient permissions to use the Bold Page Builder editor, but the potential impact is high due to the potential for privilege escalation if an administrator views the content."
}