CVE-2025-22759

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:boldgrid:post_and_page_builder_by_boldgrid_-_visual_drag_and_drop_editor:*:*:*:*:*:wordpress:*:*

History

19 Mar 2025, 17:53

Type Values Removed Values Added
First Time Boldgrid post And Page Builder By Boldgrid - Visual Drag And Drop Editor
Boldgrid
Summary
  • (es) Vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web ('Cross-site Scripting') en BoldGrid Post and Page Builder de BoldGrid – Visual Drag and Drop Editor permite XSS almacenado. Este problema afecta a Post and Page Builder de BoldGrid – Visual Drag and Drop Editor: desde n/a hasta 1.27.4.
References () https://patchstack.com/database/wordpress/plugin/post-and-page-builder/vulnerability/wordpress-post-and-page-builder-by-boldgrid-visual-drag-and-drop-editor-plugin-1-27-4-cross-site-scripting-xss-vulnerability?_s_id=cve - () https://patchstack.com/database/wordpress/plugin/post-and-page-builder/vulnerability/wordpress-post-and-page-builder-by-boldgrid-visual-drag-and-drop-editor-plugin-1-27-4-cross-site-scripting-xss-vulnerability?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:boldgrid:post_and_page_builder_by_boldgrid_-_visual_drag_and_drop_editor:*:*:*:*:*:wordpress:*:*

15 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 16:15

Updated : 2025-03-19 17:53


NVD link : CVE-2025-22759

Mitre link : CVE-2025-22759

CVE.ORG link : CVE-2025-22759


JSON object : View

Products Affected

boldgrid

  • post_and_page_builder_by_boldgrid_-_visual_drag_and_drop_editor
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')