Junglewise Threat Intelligence

CVE-2026-62110: Bold Page Builder Cross Site Scripting in contributor role

CVE-2026-62110 · Severity: medium · CVSS 6.5 · Published 2026-09-11

Technologies: Bold Themes Bold Page Builder.

Executive brief

Bold Page Builder is a WordPress plugin used to create and design website pages. A contributor-level user can inject malicious scripts that execute in the browsers of other site visitors, potentially stealing sensitive data or hijacking accounts. The vulnerability affects versions up to 5.9.9 and is fixed in version 5.9.10.

Technical details

A Cross Site Scripting (XSS) vulnerability exists in Bold Page Builder up to version 5.9.9 that allows attackers with contributor-level privileges to inject malicious scripts into the application. The vulnerability is stored/persistent in nature, requiring a privileged user to perform an action (such as crafting a malicious page or form submission) as the initial vector. Once injected, the malicious script executes in the context of other users' browsers when they visit the affected page, potentially enabling session hijacking, credential theft, or malware distribution. The issue was reported on September 6, 2026, and patched in version 5.9.10, released September 11, 2026. CVSS score is 6.5 (medium severity).

Affected products

  • Bold Themes Bold Page Builder <=5.9.9

Timeline

  • 2026-09-06: disclosed: Vulnerability reported to Patchstack by LevinityCyber
  • 2026-09-11: advisory: Patchstack early warning and public advisory published
  • 2026-09-11: patched: Fixed in version 5.9.10

References