Extension WordPress
Vulnérabilités Page Builder: Pagelayer – Drag and Drop website builder
Cette page rassemble les failles publiées pour Page Builder: Pagelayer – Drag and Drop website builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Page Builder: Pagelayer – Drag and Drop website builder
30 fiches
Pagelayer <= 2.0.9 – Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_save_content AJAX handler allowing users with basic…
*-2.0.9
2.1.0
12/06/2026
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping.…
*-2.0.9
2.1.0
12/06/2026
Page Builder: Pagelayer <= 2.0.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes
The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and including, 2.0.8. This is due to an incomplete event handler blocklist in…
*-2.0.8
2.0.9
07/04/2026
Pagelayer <= 2.0.7 – Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.0.7. This is due to the contact form…
*-2.0.7
2.0.8
27/03/2026
PageLayer <= 2.0.8 – Authenticated (Contributor+) Information Exposure
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with Contributor-level access and…
*-2.0.8
2.0.9
12/03/2026
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 – Authenticated (Author+) Insecure Direct Object Reference
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.5 via the pagelayer_replace_page function due to missing validation on a…
*-2.0.5
2.0.6
12/11/2025
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 – Reflected Cross-Site Scripting via login_url Parameter
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘login_url’ parameter in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output…
*-2.0.0
2.0.1
23/05/2025
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.0.0 due to insufficient input sanitization and…
*-2.0.0
2.0.1
23/05/2025
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 – Missing Authorization to Authenticated (Contributor+) Post Publication
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayer_save_content() function in all versions up to, and including, 1.9.8. This makes it…
*-1.9.8
2.0.0
12/03/2025
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 – Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can…
*-1.9.8
1.9.9
11/03/2025
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 – Cross-Site Request Forgery (CSRF) To Post Contents Modification
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the…
*-1.9.8
1.9.9
09/03/2025
PageLayer <= 1.9.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.9.4
1.9.5
24/01/2025
Page Builder: Pagelayer <= 1.8.9 – Authenticated (Admin+) Stored Cross-Site Scripting
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping.…
*-1.8.9
1.9.0
04/09/2024
PageLayer <= 1.8.7 – Authenticated (Administrator+) Stored Cross-Site Scripting
The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…
*-1.8.7
1.8.8
28/08/2024
Page Builder: Pagelayer <= 1.8.7 – Authenticated (Admin+) Stored Cross-Site Scripting
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping.…
*-1.8.7
1.8.8
28/07/2024
PageLayer <= 1.8.1 – Missing Authorization
The PageLayer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the pagelayer_trash_post() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers, with contributor-level…
*-1.8.1
1.8.2
28/03/2024
Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 – Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output…
*-1.8.4
1.8.5
21/03/2024
Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping.…
*-1.8.3
1.8.4
07/03/2024
Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and…
*-1.8.2
1.8.3
22/02/2024
Pagelayer <= 1.7.9 – Authenticated(Administrator+) Stored Cross-Site Scripting via Header/Footer code
The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via header/footer code in all versions up to and including 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
[*, 1.8.0)
1.8.0
31/01/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.