Extension WordPress

Vulnérabilités Bold Page Builder

Cette page rassemble les failles publiées pour Bold Page Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

35Vulnérabilités
0Critiques
31Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Bold Page Builder

35 fiches

CVE-2026-3694 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.6.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button Shortcode

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the bt_bb_button shortcode in all versions up to, and including, 5.6.8. This is due to insufficient input sanitization and output…

Versions affectées

*-5.6.8

Correctif

5.6.9

Publication

13/05/2026

CVE-2025-12159 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.4.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_raw_content shortcode in all versions up to, and including, 5.4.8 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-5.4.8

Correctif

Non indiqué

Publication

06/02/2026

CVE-2025-13463 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.5.3 – Authenticated (Author+) Stored DOM-based Cross-Site Scripting in Post Grid

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid component in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-5.5.3

Correctif

Non indiqué

Publication

06/02/2026

CVE-2025-12803 Moyenne · 6,4
Bold Page Builder

Bold Builder <= 5.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_tabs Shortcode

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shortcode in all versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-5.5.1

Correctif

Non indiqué

Publication

06/02/2026

CVE-2025-15267 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.5.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_accordion_item Shortcode

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-5.5.7

Correctif

Non indiqué

Publication

06/02/2026

CVE-2026-25451 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.6.9 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-5.6.9

Correctif

5.7.0

Publication

20/01/2026

CVE-2025-66057 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-5.5.2

Correctif

5.5.3

Publication

27/11/2025

CVE-2025-7730 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.4.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via `percentage` Parameter

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter in all versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-5.4.5

Correctif

5.4.6

Publication

23/10/2025

CVE-2025-58194 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.4.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-5.4.3

Correctif

5.4.4

Publication

27/08/2025

CVE-2025-54006 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.4.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-5.4.1

Correctif

5.4.2

Publication

16/07/2025

CVE-2024-5647 Moyenne · 6,4
Bold Page Builder

Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

Versions affectées

*-5.1.2

Correctif

5.1.3

Publication

02/07/2025

CVE-2025-5286 Moyenne · 6,4
Bold Page Builder

Bold Builder <= 5.3.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via additional_settings Parameter

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ parameter in all versions up to, and including, 5.3.6 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-5.3.6

Correctif

5.3.7

Publication

28/05/2025

CVE-2025-3715 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.3.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-text' Parameter

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-5.3.5

Correctif

5.3.6

Publication

17/05/2025

CVE-2025-47488 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-5.3.2

Correctif

5.3.3

Publication

07/05/2025

CVE-2025-47525 Moyenne · 4,4
Bold Page Builder

Bold Page Builder <= 5.3.0 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access…

Versions affectées

*-5.3.0

Correctif

5.3.1

Publication

07/05/2025

CVE-2024-53801 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-5.2.1

Correctif

5.2.2

Publication

02/12/2024

CVE-2024-47391 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.1.- – Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-5.1.0

Correctif

5.1.1

Publication

30/09/2024

CVE-2024-47298 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-5.1.1

Correctif

5.1.2

Publication

24/09/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités