PLUGIN SECURITY
Is Post And Page Builder safe?
Post and Page Builder is a standalone plugin which adds functionality to the existing TinyMCE Editor.
What this plugin does
- Slug:
post-and-page-builder - Author: BoldGrid
- 50000+ active installs
- 94/100 rating (140 reviews on wordpress.org)
- 1813239 all-time downloads
- On WordPress.org since 2017-11-16
boldgriddrag-and-dropeditorpage buildertinyMCE
Maintenance status
- Latest known version: 1.27.13
- Last updated: 2026-08-18 6:56pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 5.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
10 known CVEs on file for Post And Page Builder.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-69345 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.10 | Missing Authorization | Medium 4.3 | < 1.27.10 | 1.27.10 | 2026-01-05 | ✓ fixed in latest |
| CVE-2025-52712 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9 | Path Traversal: '.../...//' | Medium 4.2 | < 1.27.9 | 1.27.9 | 2025-07-22 | ✓ fixed in latest |
| CVE-2025-52711 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.27.9 | 1.27.9 | 2025-06-19 | ✓ fixed in latest |
| CVE-2025-52713 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9 | Server-Side Request Forgery (SSRF) | Medium 6.4 | < 1.27.9 | 1.27.9 | 2025-06-19 | ✓ fixed in latest |
| CVE-2025-22759 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 1.27.6 | 1.27.6 | 2025-01-14 | ✓ fixed in latest |
| CVE-2024-6848 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.26.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.26.7 | 1.26.7 | 2024-07-19 | ✓ fixed in latest |
| CVE-2024-4400 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.26.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.26.5 | 1.26.5 | 2024-05-15 | ✓ fixed in latest |
| CVE-2024-2888 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.26.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 1.26.3 | 1.26.3 | 2024-03-25 | ✓ fixed in latest |
+ 4 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-25480 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.24.2 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.24.2 | 1.24.2 | 2023-08-22 | ✓ fixed in latest |
| — | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.7 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.5 | < 1.27.7 | 1.27.7 | 0000-00-00 | ✓ fixed in latest |
| CVE-2024-2888 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin < 1.26.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 1.26.3 | 1.26.3 | — | ✓ fixed in latest |
| CVE-2025-0859 | Post and Page Builder by BoldGrid < 1.27.7 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function | — | Unknown | < 1.27.7 | 1.27.7 | — | ✓ fixed in latest |
How to fix it
Keep Post And Page Builder updated — 1.27.13 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Elementor Website Builder – more than just a page builder — 10000000+ active installs — 90/100 (7297)
- Kirki – Freeform Page Builder, Website Builder & Customizer — 500000+ active installs — 90/100 (81) — max PHP <8.0
- Page Builder by SiteOrigin — 400000+ active installs — 96/100 (1005) — max PHP 8.4
- Page Builder: Pagelayer – Drag and Drop website builder — 400000+ active installs — 78/100 (102) — max PHP 8.4
- Colibri Page Builder — 90000+ active installs — 88/100 (79)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.