Input validation vulnerability in Post and Page Builder by BoldGrid – Visual Drag and Drop Editor 1.26.2

The plugin called “Post and Page Builder by BoldGrid” for WordPress has a security issue where a type of attack called Stored Cross-Site Scripting can occur. This happens when the plugin doesn’t properly clean up certain types of code, making it possible for someone with access to the website to add harmful scripts that will run when someone visits a certain page. This vulnerability exists in all versions up to and including 1.26.2, and can be used by anyone with contributor-level access or higher.

Detected in:

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor fixed vulnerable versions: >= * <= 1.26.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.