CVE-2026-84028: Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settings
The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated WordPress user with the Contributor role or a higher-privileged role can inject the malicious shortcode attribute. Exploitation requires the attacker to be able to create or edit content containing Slider Elements.
When does the injected script execute?
The script executes when another user views the affected page. This makes administrators and other site visitors who load the modified page potential targets.
What should be done if the plugin cannot be updated immediately?
Restrict Contributor and other untrusted users from creating or editing content with Slider Elements, and review existing pages for untrusted values in the Slider Elements additional_settings attribute. Remove or replace suspicious content before it is viewed.