CVE-2025-22759: WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Stored XSS.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22759?
CVE-2025-22759 is classified as a medium severity vulnerability due to its potential for allowing stored Cross-site Scripting attacks.
How do I fix CVE-2025-22759?
To mitigate CVE-2025-22759, update the BoldGrid Post and Page Builder plugin to version 1.27.5 or later.
What type of vulnerability is CVE-2025-22759?
CVE-2025-22759 is a Cross-site Scripting (XSS) vulnerability resulting from improper input neutralization in the BoldGrid Post and Page Builder.
Who is affected by CVE-2025-22759?
CVE-2025-22759 affects users of the BoldGrid Post and Page Builder plugin version up to and including 1.27.4.
Can CVE-2025-22759 lead to data exposure?
Yes, CVE-2025-22759 can lead to data exposure by allowing attackers to execute malicious scripts in the context of the user's session.