Get Started

Bold Page Builder Plugin Vulnerability Exposes WordPress Sites to Authenticated Cross-Site Scripting Attacks

Bold Page Builder, a WordPress page-building plugin, contains an authenticated stored cross-site scripting (XSS) vulnerability tracked as CVE-2026-6170 with a CVSS severity score of 6.4, according to a security advisory published by Wordfence on September 30. The flaw affects all versions of Bold Page Builder through 5.7.2, allowing authenticated users to inject malicious scripts into site pages.

TL;DR: Wordfence disclosed CVE-2026-6170, a medium-severity authenticated stored XSS vulnerability in Bold Page Builder plugin versions 5.7.2 and earlier, enabling authenticated attackers to embed persistent malicious code in WordPress pages.

The advisory marks the latest in a series of WordPress plugin security disclosures affecting page-building tools agencies commonly deploy for client sites. Authenticated stored XSS vulnerabilities permit logged-in users—often with contributor- or author-level permissions—to inject JavaScript code that persists in site pages and executes when other users (including administrators) view the compromised content.

Screenshot showing WordPress plugin security advisory dashboard with CVE-2026-6170 vulnerability details highlighted

Vulnerability Classification and Risk Profile

Wordfence classified CVE-2026-6170 as a medium-severity issue with a 6.4 CVSS score. Authenticated stored XSS flaws require an attacker to possess valid site credentials before exploitation, distinguishing them from unauthenticated vulnerabilities that allow anonymous attackers to compromise sites without prior access.

The "stored" designation indicates that malicious scripts persist in the site database rather than executing only during a single session. Once injected, the code runs automatically whenever any user loads the affected page, making it a higher-impact variant than reflected XSS attacks that require victim-specific URLs.

The advisory did not specify which Bold Page Builder features contain the vulnerability or whether exploitation attempts have been observed in the wild. Wordfence has not released technical details about the specific input fields or page-builder modules affected by the flaw.

Agency Exposure and Client Site Implications

For agencies managing WordPress development services across multiple client accounts, authenticated XSS vulnerabilities present credential-management risks even when proper user role hierarchies are in place. Contributor-level users—a permission tier agencies often grant to client content editors—can typically create and save posts without publishing them, providing an injection point for malicious code.

The vulnerability affects version 5.7.2 and earlier releases. The advisory did not confirm whether a patched version has been released or provide a remediation timeline. Agencies running Bold Page Builder on client sites should monitor the plugin's official repository for security updates and audit user roles to ensure contributor-level access is restricted to trusted personnel.

WordPress plugin vulnerabilities have accelerated in disclosure frequency throughout 2026. WordPress Launches Core Security Initiative to Accelerate Vulnerability Detection Ahead of AI-Enabled Exploits reported the platform's expanded security review infrastructure in response to faster exploit development cycles. WordPress Plugin Exploits Launch Within Hours of Disclosure, New Security Guidance Warns Agencies documented the compressed window between public disclosure and active exploitation for high-severity flaws.

XSS vulnerabilities in page builders have proven particularly attractive to attackers due to the broad permissions these tools require to manipulate page structure and content. Two Critical WordPress Plugin Vulnerabilities Drive 440,000 Exploitation Attempts Across 6 Million Sites detailed Elementor Pro and Super Forms file-upload flaws that generated more than 440,000 exploitation attempts following disclosure.

The Takeaway

Agencies should immediately inventory client sites running Bold Page Builder versions 5.7.2 or earlier and monitor the plugin's repository for security patches. While the medium severity rating and authentication requirement reduce immediate risk compared to critical unauthenticated flaws, stored XSS vulnerabilities still enable privilege escalation and persistent site compromise when exploited. Agencies should audit contributor-level user accounts on affected sites and consider temporarily restricting page-builder access to administrator roles until a patched version ships. The advisory's sparse technical detail suggests Wordfence is withholding exploitation specifics pending vendor remediation—a standard responsible disclosure practice that gives agencies a narrow window to identify and secure vulnerable installations before attack techniques become public. For agencies running white-label WordPress development operations, adding CVE-2026-6170 to internal security monitoring dashboards alongside recent plugin vulnerabilities provides a clearer picture of which page-builder tools carry elevated maintenance obligations across client portfolios.