Extension WordPress
Vulnérabilités Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
Cette page rassemble les failles publiées pour Post and Page Builder by BoldGrid – Visual Drag and Drop Editor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
10 fiches
Post and Page Builder by BoldGrid <= 1.27.9 – Missing Authorization
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.27.9.…
*-1.27.9
1.27.10
05/01/2026
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 – Authenticated (Contributor+) Path Traversal
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.8. This makes it possible for authenticated attackers, with Contributor-level…
*-1.27.8
1.27.9
22/07/2025
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 – Cross-Site Request Forgery
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.27.8. This is due to missing or incorrect nonce…
*-1.27.8
1.27.9
19/06/2025
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 – Authenticated (Contributor+) Server-Side Request Forgery
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.27.8. This makes it possible for authenticated attackers, with…
*-1.27.8
1.27.9
19/06/2025
Post and Page Builder by BoldGrid <= 1.27.6 – Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.6 via the template_via_url() function. This makes it possible for…
*-1.27.6
1.27.7
05/02/2025
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.27.5 due to insufficient input sanitization and output escaping. This…
*-1.27.5
1.27.6
14/01/2025
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via File Upload
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 1.26.6 due to insufficient input sanitization…
*-1.26.6
1.26.7
20/07/2024
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 – Authenticated (Contributer+) Stored Cross-Site Scripting
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.26.4 due to insufficient input sanitization…
*-1.26.4
1.26.5
15/05/2024
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.26.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Block HTML in all versions up to, and including, 1.26.2 due to insufficient input sanitization…
*-1.26.2
1.26.3
25/03/2024
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.24.1 – Cross-Site Request Forgery via submitDefaultEditor
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.24.1. This is due to missing or incorrect nonce validation…
*-1.24.1
1.24.2
22/08/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.