BoldGrid Vulnerabilities and Affected Products
Vulnerabilities associated with Post and Page Builder by BoldGrid.
Products
Clear product- W3 Total Cache14 vulnerabilities
- Client Invoicing by Sprout Invoices8 vulnerabilities
- Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid6 vulnerabilities
- Post and Page Builder by BoldGrid5 vulnerabilities
- Post and Page Builder by BoldGrid – Visual Drag and Drop Editor5 vulnerabilities
- Sprout Clients4 vulnerabilities
- BoldGrid Easy SEO – Simple and Effective SEO2 vulnerabilities
- Total Upkeep2 vulnerabilities
- total_upkeep2 vulnerabilities
- weForms2 vulnerabilities
- weForms – Easy Drag & Drop Contact Form Builder For WordPress2 vulnerabilities
- Help Scout1 vulnerability
- w3_total_cache1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-69345MEDIUM | WordPress Post and Page Builder by BoldGrid plugin <= 1.27.9 - Broken Access Control vulnerabilityMissing Authorization vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.9. CWE-862Jan 6, 2026 | CVSS4.3v3.1 | EPSS0.158% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-52712MEDIUM | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 - Path Traversal VulnerabilityPath Traversal: '.../...//' vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Path Traversal.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.8. CWE-35Aug 14, 2025 | CVSS4.2v3.1 | EPSS0.219% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-52713MEDIUM | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.8 - Server Side Request Forgery (SSRF) VulnerabilityServer-Side Request Forgery (SSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Server Side Request Forgery.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.8. CWE-918Jun 20, 2025 | CVSS6.4v3.1 | EPSS0.164% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-52711MEDIUM | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.8 - Cross Site Request Forgery (CSRF) VulnerabilityCross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Cross Site Request Forgery.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.8. CWE-352Jun 20, 2025 | CVSS4.3v3.1 | EPSS0.121% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-22759MEDIUM | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Stored XSS.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.5. CWE-79Jan 15, 2025 | CVSS6.5v3.1 | EPSS0.314% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |