The Bold Page Builder plugin for WordPress has a security issue called Stored Cross-Site Scripting. This happens when a malicious code is inserted into the plugin’s Icon Link feature. This vulnerability affects all versions of the plugin up to 4.8.0. It can be exploited by hackers with contributor-level or higher permissions, allowing them to add harmful scripts to pages that will run whenever someone visits that page.