Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bold Themes

First CVE: Aug 30, 2019Active for: 7 yearsTotal CVEs: 52

Bold Themes develops a focused suite of WordPress plugins and page-builder tools, including the Bold Page Builder, Bello theme, and utility plugins such as Bold Timeline Lite and Cost Calculator. The vendor's vulnerabilities cluster around a small product portfolio serving the WordPress ecosystem, where exposure reflects the common attack surface of web-based plugin and theme development. Defenders tracking WordPress infrastructure should monitor this vendor's releases as part of routine plugin hygiene; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bold Themes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2019
6 years ago
Most Recent CVE
Dec 16, 2024
586 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24321CRITICAL
The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, list
Jun 1, 20219.865NONO
CVE-2021-24320MEDIUM
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_
Jun 1, 20216.134NOYES
CVE-2021-24579HIGH
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, whic
Aug 30, 20218.830NONO
CVE-2019-15821HIGH
The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data.
Aug 30, 20197.527NONO
CVE-2024-50417HIGH
Missing Authorization vulnerability in boldthemes Bold Page Builder bold-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bol
Nov 19, 20248.825NONO
CVE-2021-24820MEDIUM
The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP
Feb 28, 20226.523NONO
CVE-2024-7100MEDIUM
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button shortcode in all versions up to, and including, 5.0.2 due to i
Jul 30, 20245.420NONO
CVE-2022-4828MEDIUM
The Bold Timeline Lite WordPress plugin before 1.1.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users
Jan 30, 20235.419NONO
CVE-2021-24319MEDIUM
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-end
Jun 1, 20215.419NONO
CVE-2024-2734MEDIUM
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AI features all versions up to, and including, 4.8.8 due to insufficient in
Apr 10, 20245.418NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
85%
12%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (23.1%)
Unknown0 (0.0%)
Required20 (76.9%)
Privileges Required
Low21 (80.8%)
High2 (7.7%)
None3 (11.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.8% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bold Themes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bold Themes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bold Themes's Products

View all 4 CNAs →

Top CWEs