SecAlerts
b

boldthemes

Security Risk Profile

46
/100
medium

Security Risk Score

Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 18, 2024 to present

22
Total CVEs
11
Critical+High
0
Exploited
9
Unpatched

Threat Assessment

Avg CVSS
7.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
9
Critical/High
Risk Level
46/100
medium
🆕 4Fresh (<7d)📈 4 in Last 30 Days

Severity Distribution

Critical
9
High
2
Medium
11
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
3

Age Distribution

Common Weaknesses (CWE)

1
XSS
12

Most Affected Products

1. BoldThemes Bold Page Builder10
2. BoldThemes Celeste1
3. BoldThemes Ippsum1
4. wordpress/Ippsum1
5. BoldThemes Travelicious1

Recent Vulnerabilities

See more →
CVE-2026-6173
CVSS 6.4medium

Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'background_image' Parameter

Sep 30, 2026🔧 No Patch
CVE-2026-6170
CVSS 6.4medium

Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute

Sep 30, 2026🔧 No Patch
CVE-2026-6171
CVSS 6.4medium

Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute

Sep 30, 2026🔧 No Patch
CVE-2026-88037
CVSS 6.4medium

Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_service title

Sep 30, 2026🔧 No Patch
CVE-2026-3694
CVSS 6.4medium

Bold Page Builder <= 5.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button Shortcode

May 14, 2026🔧 No Patch
CVE-2026-27369
CVSS 8.1EPSS 0%high

WordPress Celeste theme <= 1.3.6 - PHP Object Injection vulnerability

Mar 5, 2026🔧 No Patch
CVE-2025-68541
CVSS 9.8critical

WordPress Ippsum theme <= 1.2.0 - PHP Object Injection vulnerability

Feb 20, 2026🔧 No Patch
CVE-2025-67997
CVSS 9.8critical

WordPress Travelicious theme < 1.6.7 - PHP Object Injection vulnerability

Feb 20, 2026🔧 No Patch
CVE-2026-25451
CVSS 6.5EPSS 0%medium

WordPress Bold Page Builder plugin <= 5.6.9 - Cross Site Scripting (XSS) vulnerability

Feb 19, 2026🔧 No Patch
CVE-2025-64233
CVSS 9.8critical

WordPress Codiqa theme < 1.2.8 - PHP Object Injection vulnerability

Dec 18, 2025🔧 No Patch

Monitor boldthemes in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

boldthemes Security Vulnerabilities & Risk Score | 22 CVEs | SecAlerts - SecAlerts