CVE-2025-66057: WordPress Bold Page Builder plugin <= 5.5.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows DOM-Based XSS.This issue affects Bold Page Builder: from n/a through <= 5.5.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66057?
CVE-2025-66057 is rated as a high severity vulnerability due to its potential to allow attackers to execute scripts in the context of a user's browser.
How do I fix CVE-2025-66057?
To fix CVE-2025-66057, update Bold Page Builder to version 5.5.3 or a later version that addresses this vulnerability.
What type of vulnerability is CVE-2025-66057?
CVE-2025-66057 is classified as a Cross-site Scripting (XSS) vulnerability that occurs due to improper neutralization of input during web page generation.
Which versions of Bold Page Builder are affected by CVE-2025-66057?
CVE-2025-66057 affects all versions of Bold Page Builder up to and including version 5.5.2.
Is WordPress also affected by CVE-2025-66057?
Yes, the WordPress Bold Page Builder plugin versions up to and including 5.5.2 are also affected by CVE-2025-66057.