Extension WordPress

Vulnérabilités Page Builder: Pagelayer – Drag and Drop website builder

Cette page rassemble les failles publiées pour Page Builder: Pagelayer – Drag and Drop website builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

30Vulnérabilités
0Critiques
30Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Page Builder: Pagelayer – Drag and Drop website builder

30 fiches

CVE-2026-2470 Moyenne · 4,3
Page Builder: Pagelayer – Drag and Drop website builder

Pagelayer <= 2.0.9 – Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_save_content AJAX handler allowing users with basic…

Versions affectées

*-2.0.9

Correctif

2.1.0

Publication

12/06/2026

CVE-2026-3297 Moyenne · 6,4
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping.…

Versions affectées

*-2.0.9

Correctif

2.1.0

Publication

12/06/2026

CVE-2026-2509 Moyenne · 6,4
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer <= 2.0.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes

The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and including, 2.0.8. This is due to an incomplete event handler blocklist in…

Versions affectées

*-2.0.8

Correctif

2.0.9

Publication

07/04/2026

CVE-2026-2442 Moyenne · 5,3
Page Builder: Pagelayer – Drag and Drop website builder

Pagelayer <= 2.0.7 – Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.0.7. This is due to the contact form…

Versions affectées

*-2.0.7

Correctif

2.0.8

Publication

27/03/2026

CVE-2026-39469 Moyenne · 4,3
Page Builder: Pagelayer – Drag and Drop website builder

PageLayer <= 2.0.8 – Authenticated (Contributor+) Information Exposure

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with Contributor-level access and…

Versions affectées

*-2.0.8

Correctif

2.0.9

Publication

12/03/2026

CVE-2025-12366 Moyenne · 4,3
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 – Authenticated (Author+) Insecure Direct Object Reference

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.5 via the pagelayer_replace_page function due to missing validation on a…

Versions affectées

*-2.0.5

Correctif

2.0.6

Publication

12/11/2025

CVE-2025-4223 Moyenne · 4,7
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 – Reflected Cross-Site Scripting via login_url Parameter

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘login_url’ parameter in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output…

Versions affectées

*-2.0.0

Correctif

2.0.1

Publication

23/05/2025

CVE-2024-13427 Moyenne · 6,4
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.0.0 due to insufficient input sanitization and…

Versions affectées

*-2.0.0

Correctif

2.0.1

Publication

23/05/2025

CVE-2025-2104 Moyenne · 4,3
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 – Missing Authorization to Authenticated (Contributor+) Post Publication

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayer_save_content() function in all versions up to, and including, 1.9.8. This makes it…

Versions affectées

*-1.9.8

Correctif

2.0.0

Publication

12/03/2025

CVE-2024-13430 Moyenne · 4,3
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 – Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can…

Versions affectées

*-1.9.8

Correctif

1.9.9

Publication

11/03/2025

CVE-2025-1926 Moyenne · 4,3
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 – Cross-Site Request Forgery (CSRF) To Post Contents Modification

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the…

Versions affectées

*-1.9.8

Correctif

1.9.9

Publication

09/03/2025

CVE-2025-24573 Moyenne · 6,4
Page Builder: Pagelayer – Drag and Drop website builder

PageLayer <= 1.9.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-1.9.4

Correctif

1.9.5

Publication

24/01/2025

CVE-2024-8618 Moyenne · 4,4
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer <= 1.8.9 – Authenticated (Admin+) Stored Cross-Site Scripting

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.8.9

Correctif

1.9.0

Publication

04/09/2024

CVE-2024-43972 Moyenne · 4,4
Page Builder: Pagelayer – Drag and Drop website builder

PageLayer <= 1.8.7 – Authenticated (Administrator+) Stored Cross-Site Scripting

The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…

Versions affectées

*-1.8.7

Correctif

1.8.8

Publication

28/08/2024

CVE-2024-8426 Moyenne · 4,4
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer <= 1.8.7 – Authenticated (Admin+) Stored Cross-Site Scripting

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.8.7

Correctif

1.8.8

Publication

28/07/2024

CVE-2024-2504 Moyenne · 6,4
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 – Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output…

Versions affectées

*-1.8.4

Correctif

1.8.5

Publication

21/03/2024

CVE-2024-2127 Moyenne · 6,4
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.8.3

Correctif

1.8.4

Publication

07/03/2024

CVE-2024-1590 Moyenne · 4,6
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and…

Versions affectées

*-1.8.2

Correctif

1.8.3

Publication

22/02/2024

CVE-2023-5124 Moyenne · 4,4
Page Builder: Pagelayer – Drag and Drop website builder

Pagelayer <= 1.7.9 – Authenticated(Administrator+) Stored Cross-Site Scripting via Header/Footer code

The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via header/footer code in all versions up to and including 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

[*, 1.8.0)

Correctif

1.8.0

Publication

31/01/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités