CVE-2024-3267
- EPSS 0.2%
- Veröffentlicht 09.04.2024 19:15:40
- Zuletzt bearbeitet 08.01.2025 18:10:33
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_list shortcode in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplie...
CVE-2024-3266
- EPSS 0.18%
- Veröffentlicht 09.04.2024 19:15:40
- Zuletzt bearbeitet 08.01.2025 18:10:17
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attribute...
CVE-2024-30442
- EPSS 0.06%
- Veröffentlicht 29.03.2024 18:15:13
- Zuletzt bearbeitet 08.01.2025 16:30:56
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.8.0.
CVE-2024-30179
- EPSS 0.19%
- Veröffentlicht 27.03.2024 12:15:10
- Zuletzt bearbeitet 08.01.2025 16:30:39
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.7.6.
CVE-2024-1160
- EPSS 0.09%
- Veröffentlicht 13.02.2024 10:15:08
- Zuletzt bearbeitet 21.11.2024 08:49:55
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for auth...
CVE-2024-1159
- EPSS 0.08%
- Veröffentlicht 13.02.2024 10:15:08
- Zuletzt bearbeitet 21.11.2024 08:49:55
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. ...
CVE-2024-1157
- EPSS 0.1%
- Veröffentlicht 13.02.2024 10:15:08
- Zuletzt bearbeitet 21.11.2024 08:49:55
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for aut...
CVE-2023-49823
- EPSS 0.16%
- Veröffentlicht 15.12.2023 16:15:45
- Zuletzt bearbeitet 21.11.2024 08:33:54
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.6.1.
CVE-2022-2089
- EPSS 0.21%
- Veröffentlicht 11.07.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:18
The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2021-24579
- EPSS 0.78%
- Veröffentlicht 30.08.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:53:20
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not...