Boldgrid is a WordPress-focused platform offering a suite of plugins for website building, caching, content management, and SEO optimization that serve small-to-medium web publishers and agencies. The vendor's vulnerability profile concentrates in WordPress application plugins and recurs through web-layer weakness classes including cross-site scripting, information disclosure, authorization failures, and cross-site request forgery—flaws characteristic of plugin-based extensibility and user-input handling in dynamic content management. Although the product portfolio is narrow, these plugins achieve meaningful deployment across WordPress sites, elevating their visibility in the web-application security landscape. Public exploit code tends to be available for vulnerabilities affecting this vendor, reflecting the accessibility of WordPress installations as research and attack targets. Defenders should prioritize updates for any deployed Boldgrid plugins and treat web-input validation issues in this vendor's stack as high-priority; current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boldgrid over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2010CRITICAL WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability | Feb 12, 2020 | 9.8 | 88 | NO | YES |
CVE-2026-9282HIGH The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for u | Jul 11, 2026 | 7.5 | 49 | NO | YES |
CVE-2019-6715HIGH pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data | Apr 1, 2019 | 7.5 | 46 | NO | YES |
CVE-2026-57623CRITICAL Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | Jul 2, 2026 | 9.0 | 37 | NO | NO |
CVE-2020-36848HIGH The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ | Jul 12, 2025 | 7.5 | 34 | NO | YES |
CVE-2024-12008HIGH The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it | Jan 14, 2025 | 7.5 | 32 | NO | YES |
CVE-2021-24452MEDIUM The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the | Jul 19, 2021 | 6.1 | 31 | NO | YES |
CVE-2021-24436MEDIUM The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions | Jul 19, 2021 | 6.1 | 30 | NO | YES |
CVE-2026-27384CRITICAL Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issu | Mar 5, 2026 | 9.0 | 29 | NO | NO |
CVE-2024-12365HIGH The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and | Jan 14, 2025 | 8.5 | 28 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boldgrid.
Media articles that mention a CVE ID that affects a product developed by Boldgrid — matched by CVE ID, not by vendor name.