See how bold page builder compares to other vendors in security performance
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcodecontent' parameter of the btbbshortcode shortcode in all versions up to, and including, 5.9.6. This is due to a bypassable security filter (btbbsavepre) that can be circumvented via null byte injection, combined with insufficient output sanitization of base64-decoded content in the btbbrawcontent shortcode handler. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.