Extension WordPress
Vulnérabilités Page Builder: Pagelayer – Drag and Drop website builder, page 2
Cette page rassemble les failles publiées pour Page Builder: Pagelayer – Drag and Drop website builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Page Builder: Pagelayer – Drag and Drop website builder
30 fiches
PageLayer <= 1.7.8 – Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient…
*-1.7.8
1.7.9
03/01/2024
Page Builder: Pagelayer <= 1.7.9 – Authenticated (Admin+) Stored Cross-Site Scripting
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping.…
*-1.7.9
1.8.1
24/12/2023
PageLayer <= 1.7.7 – Cross-Site Request Forgery via pagelayer_load_plugin
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.7. This is due to missing or incorrect nonce validation on the…
*-1.7.7
1.7.8
01/12/2023
Page Builder: Pagelayer <= 1.7.7 – Authenticated (Author+) Stored Cross-Site Scripting via Header/Footer
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via header/footer post content in all versions up to, and including, 1.7.7 due to insufficient input sanitization and output…
*-1.7.7
1.7.8
25/09/2023
Page Builder: Pagelayer – Drag and Drop website builder <= 1.7.6 – Missing Authorization to Stored Cross-Site Scripting
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pagelayer_save_post() function in all versions up to, and including, 1.7.6.…
*-1.7.6
1.7.7
25/09/2023
PageLayer <= 1.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ pagelayer_header_code’, 'pagelayer_body_code', and 'pagelayer_footer_code' parameters in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible…
[*, 1.7.7)
1.7.7
13/09/2023
Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 – Reflected Cross-Site Scripting via Color Settings
PageLayer before 1.3.5 allows reflected XSS via color settings.
[*, 1.3.5)
1.3.5
10/12/2020
Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 – Reflected Cross-Site Scripting via font-size
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
[*, 1.3.5)
1.3.5
10/12/2020
Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 – Missing Authorization to Cross-Site Scripting
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces…
[*, 1.1.2)
1.1.2
28/05/2020
Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 – Cross-Site Request Forgery to Cross-Site Scripting
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.
[*, 1.1.2)
1.1.2
28/05/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.