Extension WordPress

Vulnérabilités Bold Page Builder, page 2

Cette page rassemble les failles publiées pour Bold Page Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

35Vulnérabilités
0Critiques
31Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Bold Page Builder

35 fiches

CVE-2024-7100 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 5.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button Shortcode

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-5.0.2

Correctif

5.0.3

Publication

29/07/2024

CVE-2024-2735 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 4.8.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via "Price List" Element

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Price List' element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-4.8.8

Correctif

4.8.9

Publication

09/04/2024

CVE-2024-2733 Moyenne · 5,4
Bold Page Builder

Bold Page Builder <= 4.8.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Separator Element

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Separator" element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-4.8.8

Correctif

4.8.9

Publication

09/04/2024

CVE-2024-3267 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 4.8.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_price_list Shortcode

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_list shortcode in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-4.8.8

Correctif

4.8.9

Publication

05/04/2024

CVE-2024-1159 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 4.8.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Raw Content

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This…

Versions affectées

*-4.8.0

Correctif

4.8.1

Publication

12/02/2024

CVE-2023-49823 Moyenne · 6,4
Bold Page Builder

Bold Page Builder <= 4.6.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-4.6.1

Correctif

4.7.0

Publication

05/12/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités