plugin

Pagelayer Vulnerabilities

61 known security issues reported for the Pagelayer WordPress plugin. Most recent disclosed Jun 12, 2026.

3 high 28 medium

Running Pagelayer on your site? Check whether your installed version is affected.

Scan your site free

Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_save_content AJAX handler allowing users with basic post-edit capability to persist pagelayer_contact_templates metadata on...

CVSS:
4.3
Affected:
up to 2.0.9
Fixed in:
2.1.0
Disclosed:
Jun 12, 2026

CVE-2026-2470 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-leve...

CVSS:
6.4
Affected:
up to 2.0.9
Fixed in:
2.1.0
Disclosed:
Jun 12, 2026

CVE-2026-3297 on NVD →

Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes

medium

The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and including, 2.0.8. This is due to an incomplete event handler blocklist in the 'pagelayer_xss_content' XSS filtering function, which blocks common, but...

CVSS:
6.4
Affected:
up to 2.0.8
Fixed in:
2.0.9
Disclosed:
Apr 7, 2026

CVE-2026-2509 on NVD →

PageLayer - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' vulnerability

medium

Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' vulnerability

CVSS:
5.3
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
Mar 28, 2026

Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.0.7. This is due to the contact form handler performing placeholder substitution on attacker-controlled form fields and t...

CVSS:
5.3
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
Mar 27, 2026

CVE-2026-2442 on NVD →

PageLayer <= 2.0.8 - Authenticated (Contributor+) Information Exposure

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 2.0.8
Fixed in:
2.0.9
Disclosed:
Mar 12, 2026

CVE-2026-39469 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 2.0.6

unknown

[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.5 via the pagelayer_replace_page function due to missing validation on a user controlled key. This makes it possible for authenticated attacke...

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Nov 13, 2025

CVE-2025-12366 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.5 via the pagelayer_replace_page function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, w...

CVSS:
4.3
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Nov 12, 2025

CVE-2025-12366 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 2.0.1

unknown

[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
May 24, 2025

CVE-2024-13427 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘login_url’ parameter in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...

CVSS:
4.7
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
May 23, 2025

CVE-2025-4223 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
May 23, 2025

CVE-2024-13427 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayer_save_content() function in all versions up to, and including, 1.9.8. This makes it possible for authenticated attackers, with Contributor-level...

CVSS:
4.3
Affected:
up to 1.9.8
Fixed in:
2.0.0
Disclosed:
Mar 12, 2025

CVE-2025-2104 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.9.9

unknown

[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can be included. This makes it possible for authent...

Affected:
up to 1.9.9
Fixed in:
1.9.9
Disclosed:
Mar 12, 2025

CVE-2024-13430 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can be included. This makes it possible for authenticate...

CVSS:
4.3
Affected:
up to 1.9.8
Fixed in:
1.9.9
Disclosed:
Mar 11, 2025

CVE-2024-13430 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the pagelayer_save_post function. This makes it possible for unauthenticated attackers to modi...

CVSS:
4.3
Affected:
up to 1.9.8
Fixed in:
1.9.9
Disclosed:
Mar 9, 2025

CVE-2025-1926 on NVD →

PageLayer <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 1.9.4
Fixed in:
1.9.5
Disclosed:
Jan 24, 2025

CVE-2025-24573 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.9.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagelayer Team PageLayer allows DOM-Based XSS. This issue affects PageLayer: from n/a through 1.9.4.

Affected:
up to 1.9.5
Fixed in:
1.9.5
Disclosed:
Jan 24, 2025

CVE-2025-24573 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.7.8

unknown

[en] Missing Authorization vulnerability in Pagelayer Team PageLayer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PageLayer: from n/a through 1.7.7.

Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
Dec 9, 2024

CVE-2023-49196 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.8.8

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pagelayer Team PageLayer allows Stored XSS.This issue affects PageLayer: from n/a through 1.8.7.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Sep 17, 2024

CVE-2024-43972 on NVD →

Page Builder: Pagelayer <= 1.8.9 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

CVSS:
4.4
Affected:
up to 1.8.9
Fixed in:
1.9.0
Disclosed:
Sep 4, 2024

CVE-2024-8618 on NVD →

PageLayer <= 1.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
4.4
Affected:
up to 1.8.7
Fixed in:
1.8.8
Disclosed:
Aug 28, 2024

CVE-2024-43972 on NVD →

Page Builder: Pagelayer <= 1.8.7 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

CVSS:
4.4
Affected:
up to 1.8.7
Fixed in:
1.8.8
Disclosed:
Jul 28, 2024

CVE-2024-8426 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.8.2

unknown

[en] Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Jun 9, 2024

CVE-2024-30465 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.8.5

unknown

[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe...

Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
Apr 9, 2024

CVE-2024-2504 on NVD →

PageLayer <= 1.8.1 - Missing Authorization

medium

The PageLayer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the pagelayer_trash_post() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary posts.

CVSS:
4.3
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Mar 28, 2024

CVE-2024-30465 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...

CVSS:
6.4
Affected:
up to 1.8.4
Fixed in:
1.8.5
Disclosed:
Mar 21, 2024

CVE-2024-2504 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-...

CVSS:
6.4
Affected:
up to 1.8.3
Fixed in:
1.8.4
Disclosed:
Mar 7, 2024

CVE-2024-2127 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.8.4

unknown

[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contrib...

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Mar 7, 2024

CVE-2024-2127 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.8.1

unknown

[en] The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Feb 27, 2024

CVE-2023-7115 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.8.3

unknown

[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

Affected:
up to 1.8.3
Fixed in:
1.8.3
Disclosed:
Feb 23, 2024

CVE-2024-1590 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

CVSS:
4.6
Affected:
up to 1.8.2
Fixed in:
1.8.3
Disclosed:
Feb 22, 2024

CVE-2024-1590 on NVD →

Pagelayer <= 1.7.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via Header/Footer code

medium

The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via header/footer code in all versions up to and including 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitr...

CVSS:
4.4
Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Jan 31, 2024

CVE-2023-5124 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.8.0

unknown

[en] The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is disallowed, such as in multi-site WordPress configurations.

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Jan 29, 2024

CVE-2023-5124 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.7.9

unknown

[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient input sanitization and o...

Affected:
up to 1.7.9
Fixed in:
1.7.9
Disclosed:
Jan 4, 2024

CVE-2023-6738 on NVD →

PageLayer <= 1.7.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient input sanitization and output...

CVSS:
5.4
Affected:
up to 1.7.8
Fixed in:
1.7.9
Disclosed:
Jan 3, 2024

CVE-2023-6738 on NVD →

Page Builder: Pagelayer <= 1.7.9 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

CVSS:
4.4
Affected:
up to 1.7.9
Fixed in:
1.8.1
Disclosed:
Dec 24, 2023

CVE-2023-7115 on NVD →

PageLayer <= 1.7.7 - Cross-Site Request Forgery via pagelayer_load_plugin

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.7. This is due to missing or incorrect nonce validation on the pagelayer_load_plugin function. This makes it possible for unauthenticated attackers to di...

CVSS:
5.3
Affected:
up to 1.7.7
Fixed in:
1.7.8
Disclosed:
Dec 1, 2023

CVE-2023-49196 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.7.8

unknown

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.7. This is due to missing or incorrect nonce validation on the pagelayer_load_plugin function. This makes it possible for unauthenticated attackers to di...

Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
Dec 1, 2023

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.7.8

unknown

[en] The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.

Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
Oct 16, 2023

CVE-2023-5087 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.7.7

unknown

[en] The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Oct 16, 2023

CVE-2023-4687 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 1.7.6 - Missing Authorization to Stored Cross-Site Scripting

high

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pagelayer_save_post() function in all versions up to, and including, 1.7.6. This makes it possible for unauthenticated attackers to inject maliciou...

CVSS:
7.2
Affected:
up to 1.7.6
Fixed in:
1.7.7
Disclosed:
Sep 25, 2023

CVE-2023-4687 on NVD →

Page Builder: Pagelayer <= 1.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via Header/Footer

medium

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via header/footer post content in all versions up to, and including, 1.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with au...

CVSS:
6.4
Affected:
up to 1.7.7
Fixed in:
1.7.8
Disclosed:
Sep 25, 2023

CVE-2023-5087 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.7.7

unknown

Update the WordPress PageLayer plugin to the latest available version (at least 1.7.7). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress PageLayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads...

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Sep 14, 2023

PageLayer <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ pagelayer_header_code’, 'pagelayer_body_code', and 'pagelayer_footer_code' parameters in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...

CVSS:
6.4
Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Sep 13, 2023

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.7.7

unknown

The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ pagelayer_header_code’, 'pagelayer_body_code', and 'pagelayer_footer_code' parameters in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Sep 13, 2023

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.3.5

unknown

[en] PageLayer before 1.3.5 allows reflected XSS via color settings.

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Jun 7, 2021

CVE-2020-36384 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.3.5

unknown

[en] PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Jun 7, 2021

CVE-2020-36383 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.1.2

unknown

[en] An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a p...

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Jan 1, 2021

CVE-2020-35947 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.1.2

unknown

[en] An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Jan 1, 2021

CVE-2020-35944 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via font-size

medium

PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.

CVSS:
6.1
Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Dec 10, 2020

CVE-2020-36383 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via Color Settings

medium

PageLayer before 1.3.5 allows reflected XSS via color settings.

CVSS:
6.1
Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Dec 10, 2020

CVE-2020-36384 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.3.5

unknown

Reflected Cross_site Scripting (XSS) vulnerability found by WordFence Threat Intelligence team in WordPress PageLayer plugin (versions <= 1.3.4).

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Dec 10, 2020

Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Cross-Site Request Forgery to Cross-Site Scripting

high

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.

CVSS:
8.8
Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
May 28, 2020

CVE-2020-35944 on NVD →

Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Missing Authorization to Cross-Site Scripting

high

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a public...

CVSS:
7.4
Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
May 28, 2020

CVE-2020-35947 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.9.9

unknown
Affected:
up to 1.9.9
Fixed in:
1.9.9

CVE-2025-1926 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 2.0.0

unknown
Affected:
up to 2.0.0
Fixed in:
2.0.0

CVE-2025-2104 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.8.8

unknown
Affected:
up to 1.8.8
Fixed in:
1.8.8

CVE-2024-8426 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.9.0

unknown
Affected:
up to 1.9.0
Fixed in:
1.9.0

CVE-2024-8618 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 2.0.1

unknown
Affected:
up to 2.0.1
Fixed in:
2.0.1

CVE-2025-4223 on NVD →

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.7.7

unknown

The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &lsquo; pagelayer_header_code&rsquo;, &#039;pagelayer_body_code&#039;, and &#039;pagelayer_footer_code&#039; parameters in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes i...

Affected:
up to 1.7.7
Fixed in:
1.7.7

Page Builder: Pagelayer &#8211; Drag and Drop website builder [pagelayer] < 1.3.5

unknown

Multiple Cross-Site Scripting issues, via the font-size and color parameters of the Website Settings, were fixed in v1.3.5 of the plugin

Affected:
up to 1.3.5
Fixed in:
1.3.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database