Bold Page Builder <= 5.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via `percentage` Parameter
Bold Page Builder
Minimum safe version
5.7.0
Update to 5.7.0 or later to address 31 fixable vulnerabilities
CVE-2026-25451
Bold Page Builder <= 5.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Bold Builder <= 5.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_tabs Shortcode
Bold Page Builder <= 5.5.3 - Authenticated (Author+) Stored DOM-based Cross-Site Scripting in Post Grid
Bold Page Builder <= 5.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_accordion_item Shortcode
Bold Page Builder <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-58194
CVE-2025-54006
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
Bold Builder <= 5.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via additional_settings Parameter
Bold Page Builder <= 5.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-text' Parameter
CVE-2025-47525
CVE-2025-47488
CVE-2024-54382
CVE-2024-53801
CVE-2024-50417
CVE-2024-47391
CVE-2024-47298
CVE-2024-7100
CVE-2024-2736
CVE-2024-2734
CVE-2024-2735
CVE-2024-2733
CVE-2024-3267
CVE-2024-3266
CVE-2024-30442
CVE-2024-30179
CVE-2024-1157
CVE-2024-1160
CVE-2024-1159
CVE-2023-49823
CVE-2022-2089
CVE-2019-15821
CVE-2021-24579