Executive brief
The Bold Page Builder plugin for WordPress, used to create and design website pages, contains a vulnerability that allows authenticated contributors to inject malicious scripts into pages. When other users view these pages, the injected scripts execute in their browsers, potentially stealing sensitive data, hijacking accounts, or defacing content.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the bt_bb_raw_content shortcode handler, affecting all versions up to and including 5.9.6. The vulnerability combines a bypassable security filter (bt_bb_save_pre) that can be circumvented via null byte injection with insufficient output sanitization of base64-decoded content. Authenticated attackers with Contributor-level access and above can inject arbitrary JavaScript via the 'shortcode_content' parameter, which persists in the database and executes whenever a user accesses an injected page. No patch version was explicitly mentioned in the advisory.
Affected products
- Automattic Bold Page Builder up to and including 5.9.6
Timeline
- 2026-09-16: disclosed