The Bold Page Builder plugin for WordPress is not secure in versions up to and including 4.6.1. Attackers with contributor-level access and above can inject web scripts into pages that will run whenever a user visits the page. This occurs because of a lack of protection for user input and output.