boldthemes has 4 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.4 (medium). The most common weakness class is CWE-79 (4). Most affected products: Bold Page Builder (2), Bold Timeline Lite (1), bold-page-builder (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Weakness classes
Products
- Bold Page Builder 2
- Bold Timeline Lite 1
- bold-page-builder 1
Worst active — by depth score
CVE-2026-62110Medium· 6.5WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vulnerability36CVE-2026-5920Medium· 6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.635CVE-2026-7438Medium· 6.4The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient…35CVE-2025-15267Medium· 6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escapin…35
boldthemes vulnerabilities
CVEs affecting boldthemes, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-5920Medium· 6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6. This is due to a bypassable secur…
CVE-2026-62110Medium· 6.5WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.
CVE-2026-7438Medium· 6.4The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient…
The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient…
CVE-2025-15267Medium· 6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escapin…
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escapin…