Exposure of Bold Themes
WordPress themes78
exposure score
3,674
sites use
0
exploited
11
critical
CVEs
53 resultsCVE-2021-24321—Bello < 1.6.0 - Unauthenticated Blind SQL InjectionEPSS 66.6%CVE-2021-24320—Bello < 1.6.0 - Unauthenticated Reflected XSS & XFSEPSS 10.8%CVE-2024-54382MEDIUMWordPress Bold Page Builder plugin <= 5.1.5 - Path Traversal vulnerabilityEPSS 2.2%CVE-2024-50417MEDIUMWordPress Bold Page Builder plugin <= 5.1.3 - Broken Access Control vulnerabilityEPSS 1.9%CVE-2021-24319—Bello < 1.6.0 - Authenticated Cross-Site Scripting (XSS) and XFSEPSS 1.7%CVE-2025-60214CRITICALWordPress Goldenblatt theme < 1.3.0 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-60216CRITICALWordPress Addison theme < 1.4.8 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2024-2736MEDIUMBold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML TagsEPSS 0.5%CVE-2024-2735MEDIUMBold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via "Price List" ElementEPSS 0.5%CVE-2024-2734MEDIUMBold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via AI FeaturesEPSS 0.5%CVE-2024-2733MEDIUMBold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Separator ElementEPSS 0.5%CVE-2026-27429CRITICALWordPress Nifty theme <= 1.4.1 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-39495CRITICALWordPress Avantage Theme <= 2.4.9 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-39499CRITICALWordPress Medicare Theme <= 2.1.0 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2023-49823MEDIUMWordPress Bold Page Builder Plugin <= 4.6.1 is vulnerable to Cross Site Scripting (XSS)EPSS 0.5%CVE-2024-3266MEDIUMBold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget URL AttributeEPSS 0.4%CVE-2024-30179MEDIUMWordPress Bold Page Builder plugin <= 4.7.6 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2024-7100MEDIUMBold Page Builder <= 5.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button ShortcodeEPSS 0.4%CVE-2024-3267MEDIUMBold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_price_list ShortcodeEPSS 0.4%CVE-2024-1157MEDIUMBold Page Builder <= 4.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button URLEPSS 0.4%
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →