CVE-2026-84021: Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_icon URL
The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A WordPress user with the Contributor role or any higher-privileged role can exploit it by supplying a crafted URL in affected Bold Page Builder button, headline, or icon content.
When does the injected script execute?
The script executes when a user clicks the affected link. This is a stored XSS issue, so the crafted content can affect later visitors or administrators who interact with the link.
Which plugin versions are affected?
Bold Page Builder versions before 5.9.8 are affected. Updating to version 5.9.8 or later removes the identified vulnerable version range.