What is CVE-2026-2357?
A Stored Cross-Site Scripting vulnerability has been identified in the Bold Page Builder plugin for WordPress. Authenticated attackers can inject malicious scripts via the 'bt_bb_shortcode' shortcode due to insufficient input sanitization and output escaping. Users should update to the latest plugin version.
Azərbaycanca: WordPress Bold Page Builder plugin-də Stored Cross-Site Scripting zəifliyi aşkarlanıb. 'bt_bb_shortcode' qısa kodu vasitəsilə autentifikasiya olunmuş hücumçulara zərərli skript yerləşdirməyə imkan verir. Plugi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Does exploiting CVE-2026-2357 in the WordPress Bold Page Builder plugin require the attacker to be authenticated?
Yes, CVE-2026-2357 allows authenticated attackers to perform Stored Cross-Site Scripting via the 'bt_bb_shortcode' shortcode.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.