CVE-2026-88037: Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_service title
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title attribute of the btbbservice shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
Which users need access to exploit this issue?
An attacker must be authenticated with at least Contributor-level access. No user interaction by the attacker is required after they can submit the crafted shortcode attribute.
Who is exposed when malicious content has been saved?
Any user who accesses a page containing the injected bt_bb_service shortcode can have the attacker’s script execute in their browser. The vulnerability has low confidentiality and integrity impact and no stated availability impact.
How can administrators look for possible exploitation?
Review pages and other content created or edited by Contributor-level and higher accounts for bt_bb_service shortcodes, particularly unexpected or suspicious values in their title attributes. Stored payloads remain relevant wherever an affected page is still accessible.