CVE-2025-47488: WordPress Bold Page Builder plugin <= 5.3.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder allows DOM-Based XSS. This issue affects Bold Page Builder: from n/a through 5.3.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows DOM-Based XSS.This issue affects Bold Page Builder: from n/a through <= 5.3.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47488?
CVE-2025-47488 has a high severity rating as it allows for DOM-Based Cross-Site Scripting (XSS) attacks.
How does CVE-2025-47488 affect the Bold Page Builder?
CVE-2025-47488 allows attackers to inject malicious scripts into web pages generated by Bold Page Builder versions up to 5.3.2.
What versions of Bold Page Builder are affected by CVE-2025-47488?
CVE-2025-47488 affects all versions of Bold Page Builder from n/a up to 5.3.2.
How can I fix CVE-2025-47488?
To fix CVE-2025-47488, update Bold Page Builder to the latest version that addresses this vulnerability.
What types of attacks can CVE-2025-47488 facilitate?
CVE-2025-47488 can facilitate Cross-Site Scripting (XSS) attacks that may lead to data theft or session hijacking.