CVE-2026-6173: Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'background_image' Parameter
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backgroundimage' parameter of the plugin's btbbsection shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
An attacker must be authenticated to WordPress with Contributor-level access or higher. They can inject script through the background_image parameter of the bt_bb_section shortcode.
Which installations are affected?
Bold Page Builder versions up to and including 5.7.2 are affected. The issue applies where users with Contributor-level or higher roles can create or modify content containing the vulnerable shortcode.
What is the impact after malicious content is saved?
The injected script executes whenever a user visits the affected page. This can expose or alter information available in the visitor's browser session, including for higher-privileged WordPress users who view the page.