CVE-2024-47391: WordPress Bold Page Builder plugin < 5.1.1 - Cross Site Scripting (XSS) vulnerability
Published Oct 5, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through < 5.1.1.
Affected Software
1 affected component
Bold-themes Bold Page Builder Wordpress<5.1.1
Remediation
Information
Update to 5.1.1 or a higher version.
Event History
Oct 5, 2024
CVE Published
via MITRE·02:44 PM
Data Sourced
via MITRE·02:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47391?
CVE-2024-47391 is a high severity vulnerability due to the potential for stored cross-site scripting attacks.
2
How do I fix CVE-2024-47391?
To fix CVE-2024-47391, update Bold Page Builder to version 5.1.1 or later.
3
What systems are affected by CVE-2024-47391?
CVE-2024-47391 affects all versions of Bold Page Builder prior to 5.1.1.
4
What type of vulnerability is CVE-2024-47391?
CVE-2024-47391 is classified as an improper neutralization of input during web page generation, specifically an XSS vulnerability.
5
What kind of attacks can be executed with CVE-2024-47391?
Attackers can exploit CVE-2024-47391 to execute stored cross-site scripting attacks on vulnerable installations.