CVE-2024-47298: WordPress Bold Page Builder plugin <= 5.1.1 - Cross Site Scripting (XSS) vulnerability
Published Oct 6, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through <= 5.1.1.
Affected Software
1 affected component
Bold-themes Bold Page Builder Wordpress<5.1.2
Remediation
Information
Update to 5.1.2 or a higher version.
Event History
Oct 6, 2024
CVE Published
via MITRE·11:44 AM
Data Sourced
via MITRE·11:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47298?
CVE-2024-47298 has a high severity due to its potential for Stored XSS attacks.
2
How do I fix CVE-2024-47298?
To fix CVE-2024-47298, you should update Bold Page Builder to version 5.1.2 or later.
3
What are the potential impacts of CVE-2024-47298?
The potential impacts of CVE-2024-47298 include unauthorized access to user data and phishing attacks via malicious scripts.
4
Which versions of Bold Page Builder are affected by CVE-2024-47298?
CVE-2024-47298 affects all versions of Bold Page Builder from n/a up through version 5.1.1.
5
Is my website vulnerable to CVE-2024-47298?
If you are using Bold Page Builder versions prior to 5.1.2, your website is vulnerable to CVE-2024-47298.