CVE-2025-3715: Bold Page Builder <= 5.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-text' Parameter
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3715?
CVE-2025-3715 is classified as a medium severity vulnerability due to the potential for authenticated attackers to execute stored cross-site scripting attacks.
How do I fix CVE-2025-3715?
To fix CVE-2025-3715, update the Bold Page Builder plugin to version 5.3.6 or later, which includes necessary input sanitization and output escaping.
Who is affected by CVE-2025-3715?
All users of the Bold Page Builder plugin for WordPress versions up to and including 5.3.5 are affected by CVE-2025-3715.
What type of attack can CVE-2025-3715 enable?
CVE-2025-3715 allows for stored cross-site scripting attacks, where an attacker can inject malicious scripts into web pages viewed by other users.
Is authentication required to exploit CVE-2025-3715?
Yes, CVE-2025-3715 requires an authenticated attacker to exploit the vulnerability.