Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bold-themes
Bold-themes bold Page Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Bold-themes
Bold-themes bold Page Builder Wordpress Wordpress wordpress |
Wed, 16 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6. This is due to a bypassable security filter (bt_bb_save_pre) that can be circumvented via null byte injection, combined with insufficient output sanitization of base64-decoded content in the bt_bb_raw_content shortcode handler. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
| Title | Bold Page Builder <= 5.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shortcode_content' Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-16T18:56:05.108Z
Reserved: 2026-04-08T20:44:00.842Z
Link: CVE-2026-5920
Updated: 2026-09-16T18:56:00.531Z
Status : Deferred
Published: 2026-09-16T05:16:46.913
Modified: 2026-09-16T19:17:21.523
Link: CVE-2026-5920
No data.
OpenCVE Enrichment
Updated: 2026-09-16T18:15:15Z