Extension WordPress

Vulnérabilités Page Builder: Pagelayer – Drag and Drop website builder, page 2

Cette page rassemble les failles publiées pour Page Builder: Pagelayer – Drag and Drop website builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

30Vulnérabilités
0Critiques
30Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Page Builder: Pagelayer – Drag and Drop website builder

30 fiches

CVE-2023-6738 Moyenne · 5,4
Page Builder: Pagelayer – Drag and Drop website builder

PageLayer <= 1.7.8 – Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient…

Versions affectées

*-1.7.8

Correctif

1.7.9

Publication

03/01/2024

CVE-2023-7115 Moyenne · 4,4
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer <= 1.7.9 – Authenticated (Admin+) Stored Cross-Site Scripting

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.7.9

Correctif

1.8.1

Publication

24/12/2023

CVE-2023-5087 Moyenne · 6,4
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer <= 1.7.7 – Authenticated (Author+) Stored Cross-Site Scripting via Header/Footer

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via header/footer post content in all versions up to, and including, 1.7.7 due to insufficient input sanitization and output…

Versions affectées

*-1.7.7

Correctif

1.7.8

Publication

25/09/2023

CVE-2023-4687 Élevée · 7,2
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 1.7.6 – Missing Authorization to Stored Cross-Site Scripting

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pagelayer_save_post() function in all versions up to, and including, 1.7.6.…

Versions affectées

*-1.7.6

Correctif

1.7.7

Publication

25/09/2023

Vulnérabilité Moyenne · 6,4
Page Builder: Pagelayer – Drag and Drop website builder

PageLayer <= 1.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ pagelayer_header_code’, 'pagelayer_body_code', and 'pagelayer_footer_code' parameters in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

[*, 1.7.7)

Correctif

1.7.7

Publication

13/09/2023

CVE-2020-35947 Élevée · 7,4
Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 – Missing Authorization to Cross-Site Scripting

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces…

Versions affectées

[*, 1.1.2)

Correctif

1.1.2

Publication

28/05/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités