{"id":3477,"date":"2024-04-09T16:45:17","date_gmt":"2024-04-09T16:45:17","guid":{"rendered":"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/"},"modified":"2024-04-09T16:45:17","modified_gmt":"2024-04-09T16:45:17","slug":"vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor","status":"publish","type":"post","link":"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/","title":{"rendered":"Vulnerabilidad de Cross-Site Scripting en Bold Page Builder <= 4.8.8 a trav\u00e9s del elemento 'Price List' con autenticaci\u00f3n (Contribuidor+)"},"content":{"rendered":"
La vulnerabilidad CVE-2024-2735 en el plugin Bold Page Builder para WordPress permite a atacantes autenticados con nivel de acceso de contribuidor o superior, inyectar scripts web arbitrarios en p\u00e1ginas mediante el elemento ‘Price List’. Esto podr\u00eda comprometer la seguridad de los usuarios al ejecutar scripts maliciosos en las p\u00e1ginas afectadas.<\/div>\n

<\/p>\n

La falta de sanitizaci\u00f3n de valores de entrada y de escapado de salida en los atributos proporcionados por usuarios en el plugin Bold Page Builder hasta la versi\u00f3n 4.8.8, permite a atacantes inyectar scripts maliciosos en las p\u00e1ginas. Para mitigar este riesgo, se recomienda a los usuarios actualizar el plugin a la \u00faltima versi\u00f3n disponible, evitar la utilizaci\u00f3n del elemento ‘Price List’ y mantener un monitoreo constante de las p\u00e1ginas creadas con Bold Page Builder.<\/div>\n
Es crucial que los administradores de sitios WordPress est\u00e9n al tanto de esta vulnerabilidad en Bold Page Builder y tomen las medidas necesarias para proteger sus sitios y usuarios. La implementaci\u00f3n de las soluciones recomendadas ayudar\u00e1 a prevenir posibles ataques de Cross-Site Scripting en sus p\u00e1ginas creadas con este plugin.<\/div>\n","protected":false},"excerpt":{"rendered":"

La vulnerabilidad CVE-2024-2735 en el plugin Bold Page Builder para WordPress permite a atacantes autenticados con nivel de acceso de contribuidor o superior, inyectar scripts web arbitrarios en p\u00e1ginas mediante el elemento ‘Price List’. Esto podr\u00eda comprometer la seguridad de los usuarios al ejecutar scripts maliciosos en las p\u00e1ginas afectadas. La falta de sanitizaci\u00f3n de […]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1187],"class_list":["post-3477","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-cve-2024-2735"],"yoast_head":"\nVulnerabilidad de Cross-Site Scripting en Bold Page Builder <= 4.8.8 a trav\u00e9s del elemento 'Price List' con autenticaci\u00f3n (Contribuidor+) - SeguridadWordPress.es<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vulnerabilidad de Cross-Site Scripting en Bold Page Builder <= 4.8.8 a trav\u00e9s del elemento 'Price List' con autenticaci\u00f3n (Contribuidor+) - SeguridadWordPress.es\" \/>\n<meta property=\"og:description\" content=\"La vulnerabilidad CVE-2024-2735 en el plugin Bold Page Builder para WordPress permite a atacantes autenticados con nivel de acceso de contribuidor o superior, inyectar scripts web arbitrarios en p\u00e1ginas mediante el elemento ‘Price List’. Esto podr\u00eda comprometer la seguridad de los usuarios al ejecutar scripts maliciosos en las p\u00e1ginas afectadas. La falta de sanitizaci\u00f3n de […]\" \/>\n<meta property=\"og:url\" content=\"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/\" \/>\n<meta property=\"og:site_name\" content=\"SeguridadWordPress.es\" \/>\n<meta property=\"article:published_time\" content=\"2024-04-09T16:45:17+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/\",\"url\":\"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/\",\"name\":\"Vulnerabilidad de Cross-Site Scripting en Bold Page Builder <= 4.8.8 a trav\u00e9s del elemento 'Price List' con autenticaci\u00f3n (Contribuidor+) - SeguridadWordPress.es\",\"isPartOf\":{\"@id\":\"http:\/\/127.0.0.1\/#website\"},\"datePublished\":\"2024-04-09T16:45:17+00:00\",\"dateModified\":\"2024-04-09T16:45:17+00:00\",\"author\":{\"@id\":\"\"},\"breadcrumb\":{\"@id\":\"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\/\/127.0.0.1\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Vulnerabilidad de Cross-Site Scripting en Bold Page Builder <= 4.8.8 a trav\u00e9s del elemento 'Price List' con autenticaci\u00f3n (Contribuidor+)\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\/\/127.0.0.1\/#website\",\"url\":\"http:\/\/127.0.0.1\/\",\"name\":\"SeguridadWordPress.es\",\"description\":\"Recopilaci\u00f3n de vulnerabilidades WordPress.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/127.0.0.1\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vulnerabilidad de Cross-Site Scripting en Bold Page Builder <= 4.8.8 a trav\u00e9s del elemento 'Price List' con autenticaci\u00f3n (Contribuidor+) - SeguridadWordPress.es","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/","og_locale":"en_US","og_type":"article","og_title":"Vulnerabilidad de Cross-Site Scripting en Bold Page Builder <= 4.8.8 a trav\u00e9s del elemento 'Price List' con autenticaci\u00f3n (Contribuidor+) - SeguridadWordPress.es","og_description":"La vulnerabilidad CVE-2024-2735 en el plugin Bold Page Builder para WordPress permite a atacantes autenticados con nivel de acceso de contribuidor o superior, inyectar scripts web arbitrarios en p\u00e1ginas mediante el elemento ‘Price List’. Esto podr\u00eda comprometer la seguridad de los usuarios al ejecutar scripts maliciosos en las p\u00e1ginas afectadas. La falta de sanitizaci\u00f3n de […]","og_url":"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/","og_site_name":"SeguridadWordPress.es","article_published_time":"2024-04-09T16:45:17+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/","url":"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/","name":"Vulnerabilidad de Cross-Site Scripting en Bold Page Builder <= 4.8.8 a trav\u00e9s del elemento 'Price List' con autenticaci\u00f3n (Contribuidor+) - SeguridadWordPress.es","isPartOf":{"@id":"http:\/\/127.0.0.1\/#website"},"datePublished":"2024-04-09T16:45:17+00:00","dateModified":"2024-04-09T16:45:17+00:00","author":{"@id":""},"breadcrumb":{"@id":"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/127.0.0.1\/vulnerabilidad-de-cross-site-scripting-en-bold-page-builder-4-8-8-a-traves-del-elemento-price-list-con-autenticacion-contribuidor\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/127.0.0.1\/"},{"@type":"ListItem","position":2,"name":"Vulnerabilidad de Cross-Site Scripting en Bold Page Builder <= 4.8.8 a trav\u00e9s del elemento 'Price List' con autenticaci\u00f3n (Contribuidor+)"}]},{"@type":"WebSite","@id":"http:\/\/127.0.0.1\/#website","url":"http:\/\/127.0.0.1\/","name":"SeguridadWordPress.es","description":"Recopilaci\u00f3n de vulnerabilidades WordPress.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/127.0.0.1\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"}]}},"amp_enabled":true,"_links":{"self":[{"href":"http:\/\/127.0.0.1\/wp-json\/wp\/v2\/posts\/3477"}],"collection":[{"href":"http:\/\/127.0.0.1\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/127.0.0.1\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"http:\/\/127.0.0.1\/wp-json\/wp\/v2\/comments?post=3477"}],"version-history":[{"count":0,"href":"http:\/\/127.0.0.1\/wp-json\/wp\/v2\/posts\/3477\/revisions"}],"wp:attachment":[{"href":"http:\/\/127.0.0.1\/wp-json\/wp\/v2\/media?parent=3477"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/127.0.0.1\/wp-json\/wp\/v2\/categories?post=3477"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/127.0.0.1\/wp-json\/wp\/v2\/tags?post=3477"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}