CVE-2026-100510: WordPress Post and Page Builder by BoldGrid plugin <= 1.27.14 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
Affected Software
1 affected component
BoldGrid Post and Page Builder by BoldGrid<=1.27.14
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editorto a version that resolves this vulnerability.Fixed in 1.27.15
Event History
Sep 30, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
The vulnerability affects BoldGrid Post and Page Builder by BoldGrid versions 1.27.14 and earlier.
2
Does exploiting this issue require an account or elevated permissions?
No. The issue is described as unauthenticated XSS, so an attacker does not need to authenticate before attempting exploitation.
3
What user interaction is involved in exploitation?
The supplied CVSS vector indicates user interaction is required. An attacker would need a user to interact with attacker-controlled content for the XSS to execute.