WordPress · Bold Page Builder · CVE-2026-6170
**Name of the Vulnerable Software and Affected Versions**
Bold Page Builder versions prior to 5.7.3
**Description**
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping on user-supplied attributes. Authenticated attackers with Contributor-level access and above can inject arbitrary web scripts into pages via the `images` parameter of the `bt bb css image grid` shortcode. These scripts execute whenever a user accesses the affected page.
**Recommendations**
Update the plugin to version 5.7.3 or later.
As a temporary mitigation, restrict the use of the `images` parameter within the `bt bb css image grid` shortcode for users with Contributor-level access.