CVE-2026-88037 Overview
The Bold Page Builder plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability in the bt_bb_service shortcode. The flaw affects all versions up to and including 5.7.2. Authenticated users with Contributor-level access or higher can inject arbitrary JavaScript through the shortcode's title attribute. The injected scripts execute in the browsers of any user who visits a page containing the malicious shortcode. The vulnerability is tracked as [CWE-79] and stems from insufficient input sanitization and output escaping on user-supplied attributes.
Critical Impact
Authenticated contributors can persist arbitrary JavaScript into published pages, enabling session theft, redirects, or administrative account takeover when higher-privileged users view the affected content.
Affected Products
- Bold Page Builder plugin for WordPress
- All versions up to and including 5.7.2
- Sites permitting Contributor-level or higher registration
Discovery Timeline
- 2026-09-30 - CVE-2026-88037 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-88037
Vulnerability Analysis
The Bold Page Builder plugin exposes a set of custom shortcodes used to build page layouts. The bt_bb_service shortcode accepts a title attribute rendered directly into the HTML output. The plugin fails to sanitize this attribute on input and does not escape it on output. An authenticated attacker can embed HTML or JavaScript payloads inside the attribute value. When any visitor loads the page containing the shortcode, the browser parses and executes the injected script in the site's origin context.
Stored XSS in a page builder shortcode is particularly reachable because the payload persists in post content and executes on every render. Contributors typically cannot publish content directly, but an administrator preview or editorial review action is sufficient to trigger execution in a privileged session.
Root Cause
The root cause is missing input validation and missing output encoding on the title attribute of the bt_bb_service shortcode handler in content_elements/bt_bb_service/bt_bb_service.php. Attribute values pass through the shortcode renderer without calls to WordPress escaping functions such as esc_attr() or esc_html(). The vendor addressed the issue in the changeset published at WordPress Plugin Changeset 3526548.
Attack Vector
An authenticated attacker holding at least Contributor privileges creates or edits a post that includes the bt_bb_service shortcode with a malicious title attribute payload. The payload persists in the database as part of the post content. When an administrator, editor, or site visitor renders the page, the browser executes the script. Refer to the Wordfence Vulnerability Report for additional detail.
Detection Methods for CVE-2026-88037
Indicators of Compromise
- Post or page content containing bt_bb_service shortcodes with title attribute values that include <script>, onerror=, onload=, or javascript: substrings.
- Unexpected outbound requests from browsers viewing affected pages to attacker-controlled domains.
- New administrator accounts or altered user roles created shortly after a Contributor account submits shortcode-heavy content.
Detection Strategies
- Query the wp_posts table for post_content matching the pattern bt_bb_service combined with script-like tokens in attribute values.
- Review WordPress audit logs for Contributor-level users submitting or editing posts that use Bold Page Builder shortcodes.
- Inspect web server access logs for anomalous requests originating from rendered pages that contain the vulnerable shortcode.
Monitoring Recommendations
- Alert on plugin version drift for bold-page-builder across managed WordPress fleets until every instance is at the patched release.
- Monitor for role-elevation events and session cookie access following visits to pages authored by low-privilege users.
- Enable Content Security Policy (CSP) reporting to capture blocked inline script execution attempts on affected pages.
How to Mitigate CVE-2026-88037
Immediate Actions Required
- Update the Bold Page Builder plugin to the version released in changeset 3526548, which supersedes 5.7.2.
- Audit existing posts and pages for bt_bb_service shortcodes containing suspicious title attribute values and remove or sanitize them.
- Review Contributor, Author, and Editor accounts for legitimacy and rotate credentials for any account suspected of abuse.
Patch Information
The vendor patched the shortcode handler in content_elements/bt_bb_service/bt_bb_service.php by adding proper escaping to user-supplied attributes. Administrators should install the release that supersedes version 5.7.2. See the WordPress Plugin Changeset and the Wordfence Vulnerability Report for reference.
Workarounds
- Restrict new user registration and remove unnecessary Contributor-level accounts until the plugin is updated.
- Deploy a web application firewall rule that blocks POST requests containing bt_bb_service shortcode attribute values with HTML tags or javascript: schemes.
- Enforce a strict Content Security Policy that disallows inline scripts to limit execution of injected payloads on rendered pages.
# Configuration example: locate vulnerable shortcode instances in the database
wp db query "SELECT ID, post_title FROM wp_posts WHERE post_content LIKE '%bt_bb_service%' AND post_content REGEXP '(<script|onerror=|onload=|javascript:)';"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
