- Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.4.
- Source
- audit@patchstack.com
- NVD status
- Analyzed
- Products
- post_and_page_builder_by_boldgrid_-_visual_drag_and_drop_editor
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- audit@patchstack.com
- CWE-79
- Hype score
- Not currently trending
[
  {
    "nodes": [
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:a:boldgrid:post_and_page_builder_by_boldgrid_-_visual_drag_and_drop_editor:*:*:*:*:*:wordpress:*:*",
            "vulnerable": true,
            "matchCriteriaId": "F0B2EF4D-44A9-4099-A156-1D43309ACF3B",
            "versionEndExcluding": "1.27.6"
          }
        ],
        "operator": "OR"
      }
    ]
  }
]