← Back

Pagelayer

pagelayer

19 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Pagelayer
pagelayer

CVEs (19)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pagelayer
1Pagelayer
May 27, 2025
May 15, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when...Show more
The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).Show less
1Pagelayer
1Pagelayer
May 27, 2025
May 15, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfilte...Show more
The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Pagelayer
1Pagelayer
May 26, 2025
Mar 13, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayer_save_content() function in all versions up t...Show more
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayer_save_content() function in all versions up to, and including, 1.9.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to bypass post moderation and publish posts to the site.Show less
1Pagelayer
1Pagelayer
Apr 2, 2025
Mar 12, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due...Show more
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private posts that they should not have access to.Show less
1Pagelayer
1Pagelayer
May 26, 2025
Mar 10, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validati...Show more
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the pagelayer_save_post function. This makes it possible for unauthenticated attackers to modify post contents via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.Show less
1Pagelayer
1Pagelayer
Sep 25, 2024
Sep 18, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pagelayer Team PageLayer allows Stored XSS.This issue affects PageLayer: from n/a through 1.8.7.
1Pagelayer
1Pagelayer
Nov 21, 2024
Jun 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1.
1Pagelayer
1Pagelayer
Apr 8, 2026
Apr 9, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and including, 1.8.4 due to insufficient input...Show more
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Pagelayer
1Pagelayer
Apr 8, 2026
Mar 7, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sa...Show more
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Pagelayer
1Pagelayer
Mar 27, 2025
Feb 27, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when t...Show more
The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Pagelayer
1Pagelayer
Apr 8, 2026
Feb 23, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient...Show more
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Pagelayer
1Pagelayer
May 22, 2025
Jan 29, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is di...Show more
The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is disallowed, such as in multi-site WordPress configurations.Show less
1Pagelayer
1Pagelayer
Apr 8, 2026
Jan 4, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta...Show more
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This appears to be a reintroduction of a vulnerability patched in version 1.7.7.Show less
1Pagelayer
1Pagelayer
Apr 23, 2025
Oct 16, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.
1Pagelayer
1Pagelayer
Apr 23, 2025
Oct 16, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.
1Pagelayer
1Pagelayer
Nov 21, 2024
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PageLayer before 1.3.5 allows reflected XSS via color settings.
1Pagelayer
1Pagelayer
Nov 21, 2024
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
1Pagelayer
1Pagelayer
Nov 21, 2024
Jan 1, 2021
N/A· v4
7.4 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. Thi...Show more
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.Show less
1Pagelayer
1Pagelayer
Nov 21, 2024
Jan 1, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.