Bold-themes

Bold Page Builder

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 09.04.2024 19:15:40
  • Zuletzt bearbeitet 08.04.2026 19:21:18

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_list shortcode in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplie...

  • EPSS 0.43%
  • Veröffentlicht 09.04.2024 19:15:40
  • Zuletzt bearbeitet 08.04.2026 17:18:42

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attribute...

  • EPSS 0.31%
  • Veröffentlicht 29.03.2024 18:15:13
  • Zuletzt bearbeitet 28.04.2026 19:24:01

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.8.0.

  • EPSS 0.42%
  • Veröffentlicht 27.03.2024 12:15:10
  • Zuletzt bearbeitet 28.04.2026 19:23:55

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.7.6.

  • EPSS 0.38%
  • Veröffentlicht 13.02.2024 10:15:08
  • Zuletzt bearbeitet 08.04.2026 18:20:28

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for auth...

  • EPSS 0.38%
  • Veröffentlicht 13.02.2024 10:15:08
  • Zuletzt bearbeitet 08.04.2026 19:20:33

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. ...

  • EPSS 0.39%
  • Veröffentlicht 13.02.2024 10:15:08
  • Zuletzt bearbeitet 08.04.2026 19:20:33

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for aut...

  • EPSS 0.47%
  • Veröffentlicht 15.12.2023 16:15:45
  • Zuletzt bearbeitet 28.04.2026 19:22:27

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.6.1.

Exploit
  • EPSS 0.94%
  • Veröffentlicht 11.07.2022 13:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:18

The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

Exploit
  • EPSS 8.22%
  • Veröffentlicht 30.08.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:53:20

The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not...