Bold Themes develops a focused suite of WordPress plugins and page-builder tools, including the Bold Page Builder, Bello theme, and utility plugins such as Bold Timeline Lite and Cost Calculator. The vendor's vulnerabilities cluster around a small product portfolio serving the WordPress ecosystem, where exposure reflects the common attack surface of web-based plugin and theme development. Defenders tracking WordPress infrastructure should monitor this vendor's releases as part of routine plugin hygiene; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bold Themes over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24321CRITICAL The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, list | Jun 1, 2021 | 9.8 | 65 | NO | NO |
CVE-2021-24320MEDIUM The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_ | Jun 1, 2021 | 6.1 | 34 | NO | YES |
CVE-2021-24579HIGH The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, whic | Aug 30, 2021 | 8.8 | 30 | NO | NO |
CVE-2019-15821HIGH The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data. | Aug 30, 2019 | 7.5 | 27 | NO | NO |
CVE-2024-50417HIGH Missing Authorization vulnerability in boldthemes Bold Page Builder bold-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bol | Nov 19, 2024 | 8.8 | 25 | NO | NO |
CVE-2021-24820MEDIUM The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP | Feb 28, 2022 | 6.5 | 23 | NO | NO |
CVE-2024-7100MEDIUM The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button shortcode in all versions up to, and including, 5.0.2 due to i | Jul 30, 2024 | 5.4 | 20 | NO | NO |
CVE-2022-4828MEDIUM The Bold Timeline Lite WordPress plugin before 1.1.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users | Jan 30, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-24319MEDIUM The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-end | Jun 1, 2021 | 5.4 | 19 | NO | NO |
CVE-2024-2734MEDIUM The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AI features all versions up to, and including, 4.8.8 due to insufficient in | Apr 10, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bold Themes.
Media articles that mention a CVE ID that affects a product developed by Bold Themes — matched by CVE ID, not by vendor name.