
CVE-2026-2357 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and includin… https://www.cve.org/CVERecord?id=CVE-2026-2357
Post summary
Bold Page Builder plugin is vulnerable to stored XSS through its shortcode, affecting all versions up to CVE‑2026‑2357.
