CVE-2026-25451: WordPress Bold Page Builder plugin <= 5.6.9 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through <= 5.6.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25451?
CVE-2026-25451 is classified as a high severity Cross Site Scripting (XSS) vulnerability affecting Bold Page Builder up to version 5.6.4.
How do I fix CVE-2026-25451?
To fix CVE-2026-25451, update the Bold Page Builder plugin to the latest version beyond 5.6.4.
What impact does CVE-2026-25451 have on my website?
CVE-2026-25451 allows attackers to execute arbitrary scripts in the user's browser, potentially compromising user data and site integrity.
What versions are affected by CVE-2026-25451?
CVE-2026-25451 affects Bold Page Builder plugin versions up to and including 5.6.4.
Is CVE-2026-25451 a known issue in WordPress?
Yes, CVE-2026-25451 is a known issue affecting the Bold Page Builder plugin used in WordPress.