{"id":"CVE-2026-84028","title":"The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that exe…","summary":"The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that exe…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-79"],"published":"2026-09-06","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:09:21.310","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84028","references":[{"url":"https://wpscan.com/vulnerability/6abd5d49-af3a-4515-ba33-57b56a9fba4e/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00235,"epssPercentile":0.14796,"ingestedAt":"2026-09-06T18:59:01.902Z","slug":"CVE-2026-84028","body":"## Overview\n\nThe Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}