The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, 5.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 4,265 live websites that are affected by CVE-2026-2357.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 4,265 live websites (54% of Bold Page Builder install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 137 versions ( 93% of all versions) |
| 1,037 websites | |
| 355 websites | |
| 345 websites | |
| 241 websites | |
| 200 websites | |
| 170 websites | |
| 148 websites | |
| 135 websites | |
| 113 websites | |
| 94 websites |
| .com | 1,762 websites |
| .it | 248 websites |
| .de | 209 websites |
| .org | 111 websites |
| .fr | 110 websites |
| .pl | 108 websites |
| .com.au | 83 websites |
| .co.uk | 72 websites |
| .net | 70 websites |
| .com.br | 68 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.pt | **,*** | ||
| *************.***.es | ***,*** | ||
| **********.com | ***,*** | ||
| *****.com | ***,*** | ||
| **********.com | ***,*** | ||
| ****.org | ***,*** | ||
| ***********.com | ***,*** | ||
| ***********.com | ***,*** | ||
| ************.com | ***,*** | ||
| **************.com | ***,*** |
FAQ