CVE-2025-52711: WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.8 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Cross Site Request Forgery.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.8.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Cross Site Request Forgery.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.8.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52711?
CVE-2025-52711 is classified as a Cross-Site Request Forgery (CSRF) vulnerability affecting versions of BoldGrid Post and Page Builder up to 1.27.8.
How do I fix CVE-2025-52711?
To fix CVE-2025-52711, you should update BoldGrid Post and Page Builder to the latest version above 1.27.8.
What versions of Post and Page Builder are affected by CVE-2025-52711?
CVE-2025-52711 affects BoldGrid Post and Page Builder and WordPress Post and Page Builder up to version 1.27.8.
Is my website vulnerable to CVE-2025-52711?
If you are using BoldGrid Post and Page Builder or WordPress Post and Page Builder version 1.27.8 or earlier, your website is vulnerable to CVE-2025-52711.
What can attackers do with CVE-2025-52711?
Attackers exploiting CVE-2025-52711 can perform unauthorized actions on behalf of users without their consent, compromising the integrity of the website.