Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

BoldGrid — Vulnerabilities & Security Advisories 51

Browse all 51 CVE security advisories affecting BoldGrid. AI-powered Chinese analysis, POCs, and references for each vulnerability.

BoldGrid operates as a WordPress plugin and theme provider, primarily targeting small business owners and agencies seeking an integrated website building solution. Security audits have identified forty-three distinct Common Vulnerabilities and Exposures (CVEs) associated with its software ecosystem. Historically, these flaws predominantly involve Cross-Site Scripting (XSS) and SQL Injection, stemming from insufficient input validation and improper sanitization of user-supplied data. Several incidents also highlight privilege escalation risks, where authenticated users could exploit weak access controls to perform administrative actions. The platform’s architecture, which tightly couples themes with plugins, has occasionally amplified the blast radius of individual vulnerabilities. While no massive data breaches have been publicly confirmed, the high volume of disclosed CVEs indicates a pattern of delayed patching or recurring coding errors in core components. Users are advised to maintain strict update protocols to mitigate these persistent exposure vectors.

CVE ID Title CVSS Severity Published
CVE-2026-18109 W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name — W3 Total Cache CWE-79 7.2 High 2026-08-14
CVE-2026-66708 WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability — Total Upkeep CWE-862 8.2 High 2026-08-06
CVE-2026-66695 WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability — W3 Total Cache CWE-35 6.5 Medium 2026-08-06
CVE-2026-57428 WordPress Sprout Clients plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerability — Sprout Clients CWE-79 7.1 High 2026-07-23
CVE-2026-57418 WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Access Control vulnerability — Client Invoicing by Sprout Invoices CWE-862 6.5 Medium 2026-07-13
CVE-2026-9282 W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter — W3 Total Cache CWE-22 7.5 High 2026-07-11
CVE-2026-57623 WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability — W3 Total Cache CWE-1284 9.0 Critical 2026-07-02
CVE-2026-39595 WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability — W3 Total Cache CWE-862 4.7 Medium 2026-06-17
CVE-2026-3143 Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback Cancellation — Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid CWE-862 5.3 Medium 2026-05-01
CVE-2026-39562 WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.10 - Broken Access Control vulnerability — Client Invoicing by Sprout Invoices CWE-862 5.3 Medium 2026-04-08
CVE-2026-5032 W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header — W3 Total Cache CWE-200 7.5 High 2026-04-02
CVE-2026-32484 WordPress weForms plugin <= 1.6.26 - PHP Object Injection vulnerability — weForms CWE-502 8.8 High 2026-03-25
CVE-2026-32424 WordPress Sprout Clients plugin <= 3.2.2 - Cross Site Scripting (XSS) vulnerability — Sprout Clients CWE-79 6.5 Medium 2026-03-13
CVE-2026-32401 WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.9 - Local File Inclusion vulnerability — Client Invoicing by Sprout Invoices CWE-98 7.2 High 2026-03-13
CVE-2026-2707 weForms <= 1.6.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API — weForms – Easy Drag & Drop Contact Form Builder For WordPress CWE-79 6.4 Medium 2026-03-11
CVE-2026-27384 WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability — W3 Total Cache CWE-1284 9.0 Critical 2026-03-05
CVE-2026-25364 WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.8 - Broken Access Control vulnerability — Client Invoicing by Sprout Invoices CWE-862 5.3 Medium 2026-02-19
CVE-2025-69345 WordPress Post and Page Builder by BoldGrid plugin <= 1.27.9 - Broken Access Control vulnerability — Post and Page Builder by BoldGrid CWE-862 4.3 Medium 2026-01-06
CVE-2025-69028 WordPress weForms plugin <= 1.6.25 - Broken Access Control vulnerability — weForms CWE-862 5.3 Medium 2025-12-30
CVE-2025-66118 WordPress Sprout Clients plugin <= 3.2.1 - Cross Site Scripting (XSS) vulnerability — Sprout Clients CWE-79 7.1 High 2025-12-18
CVE-2025-64227 WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.7 - PHP Object Injection vulnerability — Client Invoicing by Sprout Invoices CWE-502 9.8 Critical 2025-12-18
CVE-2025-64229 WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.7 - Broken Access Control vulnerability — Client Invoicing by Sprout Invoices CWE-862 4.3 Medium 2025-10-29
CVE-2025-52712 WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 - Path Traversal Vulnerability — Post and Page Builder by BoldGrid CWE-35 4.2 Medium 2025-08-14
CVE-2020-36848 Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download — Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid CWE-200 7.5 High 2025-07-12
CVE-2025-52713 WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.8 - Server Side Request Forgery (SSRF) Vulnerability — Post and Page Builder by BoldGrid CWE-918 6.4 Medium 2025-06-20
CVE-2025-52711 WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.8 - Cross Site Request Forgery (CSRF) Vulnerability — Post and Page Builder by BoldGrid CWE-352 4.3 Medium 2025-06-20
CVE-2025-31797 WordPress Sprout Clients plugin <= 3.2 - Cross Site Scripting (XSS) vulnerability — Sprout Clients CWE-79 6.5 Medium 2025-04-01
CVE-2025-2257 Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection — Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid CWE-78 7.2 High 2025-03-26
CVE-2024-13907 Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgery — Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid CWE-918 4.9 Medium 2025-02-27
CVE-2025-0859 Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function — Post and Page Builder by BoldGrid – Visual Drag and Drop Editor CWE-22 6.5 Medium 2025-02-06

This page lists every published CVE security advisory associated with BoldGrid. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.