CVE-2023-49823: WordPress Bold Page Builder Plugin <= 4.6.1 is vulnerable to Cross Site Scripting (XSS)
Published Dec 15, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.6.1.
Affected Software
1 affected component
Bold-themes Bold Page Builder Wordpress<=4.6.1
Remediation
Information
Update to 4.7.0 or a higher version.
Event History
Dec 15, 2023
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49823?
CVE-2023-49823 has a high severity rating due to its potential for causing stored cross-site scripting (XSS) vulnerabilities.
2
How do I fix CVE-2023-49823?
To fix CVE-2023-49823, update Bold Page Builder to the latest version beyond 4.6.1.
3
Which versions of Bold Page Builder are affected by CVE-2023-49823?
CVE-2023-49823 affects all versions of Bold Page Builder from release to 4.6.1.
4
What type of vulnerability is CVE-2023-49823?
CVE-2023-49823 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
What can attackers do with CVE-2023-49823?
Attackers can exploit CVE-2023-49823 to execute malicious scripts in the context of a user's browser, potentially compromising user data.