plugin

Post And Page Builder Vulnerabilities

21 known security issues reported for the Post And Page Builder WordPress plugin. Most recent disclosed Jan 6, 2026.

10 medium

Running Post And Page Builder on your site? Check whether your installed version is affected.

Scan your site free

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] <= 1.27.9 (unfixed)

unknown

[en] Missing Authorization vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.9.

Affected:
up to 1.27.9
Fix:
No patched version reported
Disclosed:
Jan 6, 2026

CVE-2025-69345 on NVD →

Post and Page Builder by BoldGrid <= 1.27.9 - Missing Authorization

medium

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.27.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to perf...

CVSS:
4.3
Affected:
up to 1.27.9
Fixed in:
1.27.10
Disclosed:
Jan 5, 2026

CVE-2025-69345 on NVD →

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9

unknown

[en] Path Traversal vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Path Traversal. This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.8.

Affected:
up to 1.27.9
Fixed in:
1.27.9
Disclosed:
Aug 14, 2025

CVE-2025-52712 on NVD →

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 - Authenticated (Contributor+) Path Traversal

medium

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform actions on files outside of the originally intend...

CVSS:
4.3
Affected:
up to 1.27.8
Fixed in:
1.27.9
Disclosed:
Jul 22, 2025

CVE-2025-52712 on NVD →

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Server Side Request Forgery. This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.8.

Affected:
up to 1.27.9
Fixed in:
1.27.9
Disclosed:
Jun 20, 2025

CVE-2025-52713 on NVD →

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Cross Site Request Forgery.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.8.

Affected:
up to 1.27.9
Fixed in:
1.27.9
Disclosed:
Jun 20, 2025

CVE-2025-52711 on NVD →

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 - Authenticated (Contributor+) Server-Side Request Forgery

medium

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.27.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations ori...

CVSS:
6.4
Affected:
up to 1.27.8
Fixed in:
1.27.9
Disclosed:
Jun 19, 2025

CVE-2025-52713 on NVD →

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 - Cross-Site Request Forgery

medium

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.27.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauth...

CVSS:
4.3
Affected:
up to 1.27.8
Fixed in:
1.27.9
Disclosed:
Jun 19, 2025

CVE-2025-52711 on NVD →

Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function

medium

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.6 via the template_via_url() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of...

CVSS:
6.5
Affected:
up to 1.27.6
Fixed in:
1.27.7
Disclosed:
Feb 5, 2025

CVE-2025-0859 on NVD →

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] < 1.27.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.4.

Affected:
up to 1.27.6
Fixed in:
1.27.6
Disclosed:
Jan 15, 2025

CVE-2025-22759 on NVD →

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.27.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
6.4
Affected:
up to 1.27.5
Fixed in:
1.27.6
Disclosed:
Jan 14, 2025

CVE-2025-22759 on NVD →

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] < 1.26.7

unknown

[en] The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 1.26.6 due to insufficient input sanitization and output escaping affecting the boldgrid_canvas_image AJAX endpoint. This make...

Affected:
up to 1.26.7
Fixed in:
1.26.7
Disclosed:
Jul 20, 2024

CVE-2024-6848 on NVD →

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Upload

medium

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 1.26.6 due to insufficient input sanitization and output escaping affecting the boldgrid_canvas_image AJAX endpoint. This makes it...

CVSS:
6.4
Affected:
up to 1.26.6
Fixed in:
1.26.7
Disclosed:
Jul 19, 2024

CVE-2024-6848 on NVD →

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] < 1.26.5

unknown

[en] The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.26.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit...

Affected:
up to 1.26.5
Fixed in:
1.26.5
Disclosed:
May 16, 2024

CVE-2024-4400 on NVD →

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 - Authenticated (Contributer+) Stored Cross-Site Scripting

medium

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.26.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with con...

CVSS:
6.4
Affected:
up to 1.26.4
Fixed in:
1.26.5
Disclosed:
May 15, 2024

CVE-2024-4400 on NVD →

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] < 1.26.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.26.2.

Affected:
up to 1.26.3
Fixed in:
1.26.3
Disclosed:
Mar 26, 2024

CVE-2024-2888 on NVD →

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.26.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Block HTML in all versions up to, and including, 1.26.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribut...

CVSS:
6.4
Affected:
up to 1.26.2
Fixed in:
1.26.3
Disclosed:
Mar 25, 2024

CVE-2024-2888 on NVD →

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] < 1.26.3

unknown

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Block HTML in all versions up to, and including, 1.26.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribut...

Affected:
up to 1.26.3
Fixed in:
1.26.3
Disclosed:
Mar 25, 2024

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] < 1.24.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.24.1 versions.

Affected:
up to 1.24.2
Fixed in:
1.24.2
Disclosed:
Oct 6, 2023

CVE-2023-25480 on NVD →

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.24.1 - Cross-Site Request Forgery via submitDefaultEditor

medium

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.24.1. This is due to missing or incorrect nonce validation on the submitDefaultEditor function. This makes it possible for unauthenticated attackers to...

CVSS:
4.3
Affected:
up to 1.24.1
Fixed in:
1.24.2
Disclosed:
Aug 22, 2023

CVE-2023-25480 on NVD →

Post and Page Builder by BoldGrid &#8211; Visual Drag and Drop Editor [post-and-page-builder] < 1.27.7

unknown
Affected:
up to 1.27.7
Fixed in:
1.27.7

CVE-2025-0859 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database