Loading market data...
← Back to CVE feed

CVE-2026-84028

UNKNOWN View on NVD ↗

Description

The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.

Published: Sep 06, 2026 07:16 UTC Modified: Sep 06, 2026 07:16 UTC