CVE-2025-14032
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in the 'bold_timeline_group' shortcode in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<p><strong><a href="https://bold-timeline.bold-themes.com/lite-main-demo/" rel="nofollow ugc">Bold Timeline Lite</a> – WordPress Timeline Plugin</strong></p>
<p><a href="https://bold-timeline.bold-themes.com/lite-main-demo/" rel="nofollow ugc">Bold Timeline Lite</a> is a WordPress timeline plugin that lets you show, easily, any number of events in, for example, company history, author biography, history events, life stories, work experience, step-by-step guide, events timeline or other.</p>
<p><strong><a href="https://bold-timeline.bold-themes.com/lite-main-demo/" rel="nofollow ugc">Bold Timeline Lite</a> is super easy to use!</strong></p>
<p>Our goal was to make it real easy for anyone to use by eliminating all the hassle that comes from overly complex settings. It has <a href="https://bold-timeline.bold-themes.com/lite-main-demo/" rel="nofollow ugc">5 predefined styles</a> ready for you. Choose your style, then import your own text and images and your timeline is done. In addition, you have the option to change colors, fonts and icons to reflect your particular taste and style.</p>
<p>Our <a href="https://bold-timeline.bold-themes.com/lite-main-demo/" rel="nofollow ugc">predefined styles</a>:</p>
<ul>
<li><a href="https://bold-timeline.bold-themes.com/lite-main-demo/classic-demo/" rel="nofollow ugc">Classic</a></li>
<li><a href="https://bold-timeline.bold-themes.com/lite-main-demo/retro-demo/" rel="nofollow ugc">Retro</a></li>
<li><a href="https://bold-timeline.bold-themes.com/lite-main-demo/clean-demo/" rel="nofollow ugc">Clean</a></li>
<li><a href="https://bold-timeline.bold-themes.com/lite-main-demo/travel-demo/" rel="nofollow ugc">Travel</a></li>
<li><a href="https://bold-timeline.bold-themes.com/lite-main-demo/cv-demo/" rel="nofollow ugc">CV</a></li>
</ul>
<p>This timeline has its own shortcode builder which makes it easy to use with any WordPress page builder. Bold Timeline Lite for WordPress is simple and easy to use, can be used to show any sequence of events or steps in several different ways. It is responsive and will look good on any screen size.</p>
<p><strong>Exceptional Features!</strong></p>
<ul>
<li>Latest WordPress version compatibility</li>
<li>Well organized & clean code</li>
<li>Compatible browsers: IE11, Firefox, Safari, Opera, Chrome, Edge</li>
<li>Responsive design</li>
<li><a href="https://documentation.bold-themes.com/bold-timeline-lite/" rel="nofollow ugc">Online documentation</a></li>
<li>Customer support</li>
<li>Shortcode builder</li>
<li>Great compatibility</li>
<li><a href="https://bold-timeline.bold-themes.com/lite-main-demo/" rel="nofollow ugc">5 predefined timeline styles to choose from</a></li>
<li>Colors & fonts settings</li>
<li>Icons & media settings</li>
</ul>
<p><a href="https://bold-timeline.bold-themes.com/lite-main-demo/" rel="nofollow ugc">Bold Timeline Lite</a> is used for:</p>
<ul>
<li>Company history timeline</li>
<li>Author biography timeline</li>
<li>History events timeline</li>
<li>Life stories timeline</li>
<li>Work experience timeline</li>
<li>Step-by-step guide</li>
<li>Events timeline</li>
</ul>
<p><strong>For many additional and advanced options/features you can check our <a href="https://bold-timeline.bold-themes.com/" rel="nofollow ugc">Bold Timeline Full Version</a>.</strong></p>