Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Boldgrid

First CVE: Dec 19, 2014Active for: 12 yearsTotal CVEs: 32
51.4
VTI Score
TOP TARGET

Boldgrid is a WordPress-focused platform offering a suite of plugins for website building, caching, content management, and SEO optimization that serve small-to-medium web publishers and agencies. The vendor's vulnerability profile concentrates in WordPress application plugins and recurs through web-layer weakness classes including cross-site scripting, information disclosure, authorization failures, and cross-site request forgery—flaws characteristic of plugin-based extensibility and user-input handling in dynamic content management. Although the product portfolio is narrow, these plugins achieve meaningful deployment across WordPress sites, elevating their visibility in the web-application security landscape. Public exploit code tends to be available for vulnerabilities affecting this vendor, reflecting the accessibility of WordPress installations as research and attack targets. Defenders should prioritize updates for any deployed Boldgrid plugins and treat web-input validation issues in this vendor's stack as high-priority; current exploitation activity, severity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Boldgrid over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2014
11 years ago
Most Recent CVE
Jul 11, 2026
13 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-2010CRITICAL
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
Feb 12, 20209.888NOYES
CVE-2026-9282HIGH
The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for u
Jul 11, 20267.549NOYES
CVE-2019-6715HIGH
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data
Apr 1, 20197.546NOYES
CVE-2026-57623CRITICAL
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
Jul 2, 20269.037NONO
CVE-2020-36848HIGH
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ
Jul 12, 20257.534NOYES
CVE-2024-12008HIGH
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it
Jan 14, 20257.532NOYES
CVE-2021-24452MEDIUM
The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the
Jul 19, 20216.131NOYES
CVE-2021-24436MEDIUM
The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions
Jul 19, 20216.130NOYES
CVE-2026-27384CRITICAL
Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issu
Mar 5, 20269.029NONO
CVE-2024-12365HIGH
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and
Jan 14, 20258.528NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
47%
44%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network30 (93.8%)
Unknown2 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (87.5%)
High2 (6.3%)
Unknown2 (6.3%)
User Interaction
None22 (68.8%)
Unknown2 (6.3%)
Required8 (25.0%)
Privileges Required
Low7 (21.9%)
High5 (15.6%)
None18 (56.3%)
Unknown2 (6.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
6.2% of CVEs· 98th percentile
Nuclei
5 CVEs
15.6% of CVEs· 97th percentile
ExploitDB
1 CVE
3.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Boldgrid.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Boldgrid — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Boldgrid's Products

View all 5 CNAs →

Top CWEs