CVE-2026-6170: Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's btbbcssimagegrid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
Does successful exploitation require a victim to take any action beyond viewing the affected page?
No. The attack vector indicates no user interaction is required; the injected script executes when a user accesses the page containing the malicious shortcode attribute.
What security impact is indicated beyond script execution?
The CVSS vector indicates changed scope, with low confidentiality and integrity impact and no availability impact. This means the issue is not rated as causing service disruption.