Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_save_content AJAX handler allowing users with basic post-edit capability to persist pagelayer_contact_templates metadata on...
- CVSS:
- 4.3
- Affected:
- up to 2.0.9
- Fixed in:
- 2.1.0
- Disclosed:
- Jun 12, 2026
CVE-2026-2470 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-leve...
- CVSS:
- 6.4
- Affected:
- up to 2.0.9
- Fixed in:
- 2.1.0
- Disclosed:
- Jun 12, 2026
CVE-2026-3297 on NVD →
Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes
medium
The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and including, 2.0.8. This is due to an incomplete event handler blocklist in the 'pagelayer_xss_content' XSS filtering function, which blocks common, but...
- CVSS:
- 6.4
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Apr 7, 2026
CVE-2026-2509 on NVD →
PageLayer - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' vulnerability
medium
Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' vulnerability
- CVSS:
- 5.3
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.8
- Disclosed:
- Mar 28, 2026
Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.0.7. This is due to the contact form handler performing placeholder substitution on attacker-controlled form fields and t...
- CVSS:
- 5.3
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.8
- Disclosed:
- Mar 27, 2026
CVE-2026-2442 on NVD →
PageLayer <= 2.0.8 - Authenticated (Contributor+) Information Exposure
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Mar 12, 2026
CVE-2026-39469 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.6
unknown
[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.5 via the pagelayer_replace_page function due to missing validation on a user controlled key. This makes it possible for authenticated attacke...
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Nov 13, 2025
CVE-2025-12366 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.5 via the pagelayer_replace_page function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, w...
- CVSS:
- 4.3
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Nov 12, 2025
CVE-2025-12366 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.1
unknown
[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- May 24, 2025
CVE-2024-13427 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘login_url’ parameter in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...
- CVSS:
- 4.7
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.1
- Disclosed:
- May 23, 2025
CVE-2025-4223 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.1
- Disclosed:
- May 23, 2025
CVE-2024-13427 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayer_save_content() function in all versions up to, and including, 1.9.8. This makes it possible for authenticated attackers, with Contributor-level...
- CVSS:
- 4.3
- Affected:
- up to 1.9.8
- Fixed in:
- 2.0.0
- Disclosed:
- Mar 12, 2025
CVE-2025-2104 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.9.9
unknown
[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can be included. This makes it possible for authent...
- Affected:
- up to 1.9.9
- Fixed in:
- 1.9.9
- Disclosed:
- Mar 12, 2025
CVE-2024-13430 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can be included. This makes it possible for authenticate...
- CVSS:
- 4.3
- Affected:
- up to 1.9.8
- Fixed in:
- 1.9.9
- Disclosed:
- Mar 11, 2025
CVE-2024-13430 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the pagelayer_save_post function. This makes it possible for unauthenticated attackers to modi...
- CVSS:
- 4.3
- Affected:
- up to 1.9.8
- Fixed in:
- 1.9.9
- Disclosed:
- Mar 9, 2025
CVE-2025-1926 on NVD →
PageLayer <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.5
- Disclosed:
- Jan 24, 2025
CVE-2025-24573 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.9.5
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagelayer Team PageLayer allows DOM-Based XSS. This issue affects PageLayer: from n/a through 1.9.4.
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- Jan 24, 2025
CVE-2025-24573 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.7.8
unknown
[en] Missing Authorization vulnerability in Pagelayer Team PageLayer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PageLayer: from n/a through 1.7.7.
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.8
- Disclosed:
- Dec 9, 2024
CVE-2023-49196 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.8.8
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pagelayer Team PageLayer allows Stored XSS.This issue affects PageLayer: from n/a through 1.8.7.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Sep 17, 2024
CVE-2024-43972 on NVD →
Page Builder: Pagelayer <= 1.8.9 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 1.8.9
- Fixed in:
- 1.9.0
- Disclosed:
- Sep 4, 2024
CVE-2024-8618 on NVD →
PageLayer <= 1.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 4.4
- Affected:
- up to 1.8.7
- Fixed in:
- 1.8.8
- Disclosed:
- Aug 28, 2024
CVE-2024-43972 on NVD →
Page Builder: Pagelayer <= 1.8.7 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 1.8.7
- Fixed in:
- 1.8.8
- Disclosed:
- Jul 28, 2024
CVE-2024-8426 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.8.2
unknown
[en] Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Jun 9, 2024
CVE-2024-30465 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.8.5
unknown
[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe...
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- Apr 9, 2024
CVE-2024-2504 on NVD →
PageLayer <= 1.8.1 - Missing Authorization
medium
The PageLayer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the pagelayer_trash_post() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary posts.
- CVSS:
- 4.3
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Mar 28, 2024
CVE-2024-30465 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...
- CVSS:
- 6.4
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.5
- Disclosed:
- Mar 21, 2024
CVE-2024-2504 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-...
- CVSS:
- 6.4
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.4
- Disclosed:
- Mar 7, 2024
CVE-2024-2127 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.8.4
unknown
[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contrib...
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Mar 7, 2024
CVE-2024-2127 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.8.1
unknown
[en] The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Feb 27, 2024
CVE-2023-7115 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.8.3
unknown
[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Feb 23, 2024
CVE-2024-1590 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- CVSS:
- 4.6
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.3
- Disclosed:
- Feb 22, 2024
CVE-2024-1590 on NVD →
Pagelayer <= 1.7.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via Header/Footer code
medium
The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via header/footer code in all versions up to and including 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitr...
- CVSS:
- 4.4
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Jan 31, 2024
CVE-2023-5124 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.8.0
unknown
[en] The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is disallowed, such as in multi-site WordPress configurations.
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Jan 29, 2024
CVE-2023-5124 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.7.9
unknown
[en] The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient input sanitization and o...
- Affected:
- up to 1.7.9
- Fixed in:
- 1.7.9
- Disclosed:
- Jan 4, 2024
CVE-2023-6738 on NVD →
PageLayer <= 1.7.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient input sanitization and output...
- CVSS:
- 5.4
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.9
- Disclosed:
- Jan 3, 2024
CVE-2023-6738 on NVD →
Page Builder: Pagelayer <= 1.7.9 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 1.7.9
- Fixed in:
- 1.8.1
- Disclosed:
- Dec 24, 2023
CVE-2023-7115 on NVD →
PageLayer <= 1.7.7 - Cross-Site Request Forgery via pagelayer_load_plugin
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.7. This is due to missing or incorrect nonce validation on the pagelayer_load_plugin function. This makes it possible for unauthenticated attackers to di...
- CVSS:
- 5.3
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.8
- Disclosed:
- Dec 1, 2023
CVE-2023-49196 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.7.8
unknown
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.7. This is due to missing or incorrect nonce validation on the pagelayer_load_plugin function. This makes it possible for unauthenticated attackers to di...
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.8
- Disclosed:
- Dec 1, 2023
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.7.8
unknown
[en] The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.8
- Disclosed:
- Oct 16, 2023
CVE-2023-5087 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.7.7
unknown
[en] The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Oct 16, 2023
CVE-2023-4687 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 1.7.6 - Missing Authorization to Stored Cross-Site Scripting
high
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pagelayer_save_post() function in all versions up to, and including, 1.7.6. This makes it possible for unauthenticated attackers to inject maliciou...
- CVSS:
- 7.2
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.7
- Disclosed:
- Sep 25, 2023
CVE-2023-4687 on NVD →
Page Builder: Pagelayer <= 1.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via Header/Footer
medium
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via header/footer post content in all versions up to, and including, 1.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with au...
- CVSS:
- 6.4
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.8
- Disclosed:
- Sep 25, 2023
CVE-2023-5087 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.7.7
unknown
Update the WordPress PageLayer plugin to the latest available version (at least 1.7.7).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress PageLayer Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads...
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Sep 14, 2023
PageLayer <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ pagelayer_header_code’, 'pagelayer_body_code', and 'pagelayer_footer_code' parameters in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Sep 13, 2023
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.7.7
unknown
The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ pagelayer_header_code’, 'pagelayer_body_code', and 'pagelayer_footer_code' parameters in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Sep 13, 2023
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.3.5
unknown
[en] PageLayer before 1.3.5 allows reflected XSS via color settings.
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Jun 7, 2021
CVE-2020-36384 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.3.5
unknown
[en] PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Jun 7, 2021
CVE-2020-36383 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.1.2
unknown
[en] An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a p...
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Jan 1, 2021
CVE-2020-35947 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.1.2
unknown
[en] An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Jan 1, 2021
CVE-2020-35944 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via font-size
medium
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Dec 10, 2020
CVE-2020-36383 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via Color Settings
medium
PageLayer before 1.3.5 allows reflected XSS via color settings.
- CVSS:
- 6.1
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Dec 10, 2020
CVE-2020-36384 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.3.5
unknown
Reflected Cross_site Scripting (XSS) vulnerability found by WordFence Threat Intelligence team in WordPress PageLayer plugin (versions <= 1.3.4).
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Dec 10, 2020
Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Cross-Site Request Forgery to Cross-Site Scripting
high
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.
- CVSS:
- 8.8
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- May 28, 2020
CVE-2020-35944 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Missing Authorization to Cross-Site Scripting
high
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a public...
- CVSS:
- 7.4
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- May 28, 2020
CVE-2020-35947 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.9.9
unknown
- Affected:
- up to 1.9.9
- Fixed in:
- 1.9.9
CVE-2025-1926 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.0
unknown
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
CVE-2025-2104 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.8.8
unknown
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
CVE-2024-8426 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.9.0
unknown
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
CVE-2024-8618 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.1
unknown
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
CVE-2025-4223 on NVD →
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.7.7
unknown
The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ pagelayer_header_code’, 'pagelayer_body_code', and 'pagelayer_footer_code' parameters in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes i...
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.3.5
unknown
Multiple Cross-Site Scripting issues, via the font-size and color parameters of the Website Settings, were fixed in v1.3.5 of the plugin
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5