CVE-2026-88037

CVE-2026-88037 published: The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escapin...

View full NVD advisory → ← Back to CVE watch