CVE-2024-7100
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<h4>Forever 100% Free page builder</h4>
<p>Bold Page Builder for WordPress is 100% free – there is no premium version and you can use it freely in your commercial and noncommercial projects. Even in your Premium WordPress themes.</p>
<h4>FRONT-END EDITOR | NEW FROM 2022!</h4>
<p>From Bold Builder version 4.0.0. you can easily manage your content both backend and frontend with newly added functionality. Our drag and drop Bold Page Builder just got better with adding easy to use front end editing options. Now you can view your website pages as you edit them.</p>
<span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/8ftwyKO_3ok?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span>
<blockquote>
<p><strong>Create your premium looking website using only default Twenty Seventeen or Twenty Sixteen theme and Bold Page Builder</strong></p>
<p>See Bold Page Builder in action!<br />
Check out our demo pages built with <a href="https://wordpress.org/themes/twentyseventeen/" rel="ugc">Twenty Seventeen theme</a>:</p>
<ul>
<li><a href="http://demos.bold-themes.com/demo-wedding-2017/" title="Wedding WordPress Website Demo" rel="nofollow ugc">Wedding 2017 Demo</a></li>
<li><a href="http://demos.bold-themes.com/demo-accomodation-2017/" title="Accomodation WordPress Website Demo" rel="nofollow ugc">Accommodation 2017 Demo</a></li>
<li><a href="http://demos.bold-themes.com/demo-construction-2017/" title="Construction company WordPress Website Demo" rel="nofollow ugc">Construction 2017 Demo</a></li>
</ul>
<p>Check out our demo pages built with <a href="https://wordpress.org/themes/twentysixteen/" rel="ugc">Twenty Sixteen theme</a>:</p>
<ul>
<li><a href="http://demos.bold-themes.com/demo-restaurant-2016/" title="Restaurant WordPress Website Demo" rel="nofollow ugc">Restaurant 2016 Demo</a></li>
<li><a href="http://demos.bold-themes.com/demo-handyman-2016/" title="Small Business WordPress Website Demo" rel="nofollow ugc">Handyman 2016 Demo</a></li>
<li><a href="http://demos.bold-themes.com/demo-wedding-2016/" title="Celebration WordPress Website Demo" rel="nofollow ugc">Wedding 2016 Demo</a></li>
</ul>
<p>Our demos use the following free plugins:</p>
<ul>
<li><a href="https://wordpress.org/plugins/customize-twenty-seventeen/" title="Customize Twenty Seventeen WordPress Plugin" rel="ugc">Customize Twenty Seventeen</a></li>
<li><a href="https://wordpress.org/plugins/customize-twenty-sixteen/" title="Customize Twenty Sixteen WordPress Plugin" rel="ugc">Customize Twenty Sixteen</a></li>
</ul>
<p>When you are ready for the next step, we also offer a selection of premium themes which are using Bold Page Builder: <a href="https://themeforest.net/user/boldthemes/portfolio?ref=bold-page-builder" title="BoldThemes Portfolio" rel="nofollow ugc">BoldThemes Portfolio</a>.</p>
</blockquote>
<h4>Comes with 30+ Content Elements</h4>
<p>Bold Builder – WordPress Page builder comes packed with loads of content elements – you can start building your layouts in minutes with drag and drop features and with no coding experience. And it is very easy to extend.</p>
<ul>
<li>Accordion</li>
<li>Button</li>
<li>Cost calculator</li>
<li>Headline</li>
<li>Icon</li>
<li>Image</li>
<li>Latest posts</li>
<li>Masonry image grid</li>
<li>Masonry post grid</li>
<li>Price list</li>
<li>Raw HTML/JS content</li>
<li>Separator</li>
<li>Service</li>
<li>Slider</li>
<li>Tabs</li>
<li>Text</li>
<li>Video</li>
</ul>
<h4>Ideal for theme and WordPress developers</h4>
<p>If you are a WordPress developer, feel free to extend it with your components – it features simple and intuitive API as well as a detailed developer’s documentation and examples to get you started right away.</p>
<h4>Lightning fast Visual Builder</h4>
<p>It is a speed champion and only WordPress drag and drop page builder with the instant user interface response – no more waiting and nail biting. Beats popular Visual Composer by a mile.</p>
<h4>100% Compatible with most WordPress themes</h4>
<p>Bold Builder should work with most of the themes – free or premium. In fact, all demos are developed using free themes and plugins from WordPress.org. You can import these pages and choose from a selection of carefully crafted design elements. For detailed instructions on how to install demos please read <a href="http://documentation.bold-themes.com/bold-builder/getting-started/#installing-demo-content" rel="nofollow ugc">Online Documentation </a>.</p>
<h4>Full Clipboard functionality unlike any other WordPress Page Builder plugin</h4>
<p>Do not restrict yourself to duplicating your content elements within one page like others do. Now, you can copy any content element them from one page to another and even from one site to another. Unlike with any other page builder plugin. Finally, unleash the full power of content element clipboard and make your life do much easier.</p>
<h4>Actively developed and supported</h4>
<p>Bold Page Builder is actively developed by <a href="http://www.bold-themes.com/" title="Premium WordPress Themes" rel="nofollow ugc">BoldThemes</a> , authors of a number of free and premium WordPress themes and plugins. We are committed to making it the greatest free WordPress page builder plugin ever and expect constant flow of new and exciting features.</p>
<p>Bold Builder is supported through our <a href="https://wordpress.org/support/plugin/bold-page-builder" title="Support Forum" rel="ugc">support forum</a>.</p>
<p>For detailed online documentation go to <a href="http://documentation.bold-themes.com/bold-builder/getting-started/" rel="nofollow ugc">Bold Builder Online Documentation</a>.</p>
<p>To read more about Bold Builder visit our <a href="https://bold-builder.bold-themes.com/" rel="nofollow ugc">website</a>.</p>
<p>Important: Please note that our premium themes launched before June 1, 2017 will not have all the options described in this article.</p>