CVE-2026-84022

The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 07:17

Updated : 2026-09-08 19:09


NVD link : CVE-2026-84022

Mitre link : CVE-2026-84022

CVE.ORG link : CVE-2026-84022


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')