Lucene search

K

Pagelayer Security Vulnerabilities

cve
cve

CVE-2024-30465

Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through...

6.5CVSS

6.5AI Score

0.0004EPSS

2024-06-09 11:15 AM
26
cve
cve

CVE-2024-2504

The Page Builder: Pagelayer ā€“ Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...

6.4CVSS

6.1AI Score

0.0004EPSS

2024-04-09 07:15 PM
27
cve
cve

CVE-2024-2127

The Page Builder: Pagelayer ā€“ Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

6.4CVSS

5.8AI Score

0.0004EPSS

2024-03-07 08:15 PM
30
cve
cve

CVE-2023-7115

The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite...

5.6AI Score

0.0004EPSS

2024-02-27 09:15 AM
2765
cve
cve

CVE-2024-1590

The Page Builder: Pagelayer ā€“ Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This...

4.6CVSS

5AI Score

0.0004EPSS

2024-02-23 10:15 AM
49
cve
cve

CVE-2023-5124

The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is disallowed, such as in multi-site WordPress...

4.8CVSS

5.3AI Score

0.0004EPSS

2024-01-29 03:15 PM
12
cve
cve

CVE-2023-6738

The Page Builder: Pagelayer ā€“ Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient input...

5.4CVSS

5.2AI Score

0.001EPSS

2024-01-04 04:15 AM
16
cve
cve

CVE-2023-5087

The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer...

5.4CVSS

5.5AI Score

0.0004EPSS

2023-10-16 08:15 PM
23
cve
cve

CVE-2023-4687

The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled...

6.1CVSS

6.4AI Score

0.001EPSS

2023-10-16 08:15 PM
16
cve
cve

CVE-2020-36384

PageLayer before 1.3.5 allows reflected XSS via color...

6.1CVSS

6AI Score

0.001EPSS

2021-06-07 11:15 AM
16
cve
cve

CVE-2020-36383

PageLayer before 1.3.5 allows reflected XSS via the font-size...

6.1CVSS

6AI Score

0.001EPSS

2021-06-07 11:15 AM
17
4
cve
cve

CVE-2020-35944

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to...

8.8CVSS

8.6AI Score

0.002EPSS

2021-01-01 04:15 AM
69
1
cve
cve

CVE-2020-35947

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce...

7.4CVSS

7.2AI Score

0.001EPSS

2021-01-01 04:15 AM
64
3