CVE-2026-39469
Page Builder: Pagelayer – Drag and Drop website builder
Minimum safe version
2.0.9
Update to 2.0.9 or later to address 33 fixable vulnerabilities
Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes
Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'
CVE-2025-12366
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter
CVE-2024-13427
Page Builder: Pagelayer <= 1.8.9 - Authenticated (Admin+) Stored Cross-Site Scripting
Page Builder: Pagelayer <= 1.8.7 - Authenticated (Admin+) Stored Cross-Site Scripting
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication
CVE-2024-13430
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification
CVE-2025-24573
CVE-2024-43972
CVE-2024-30465
CVE-2024-2504
CVE-2024-2127
CVE-2023-7115
CVE-2024-1590
Pagelayer <= 1.7.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via Header/Footer code
PageLayer < 1.7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2023-6738
PageLayer <= 1.7.7 - Cross-Site Request Forgery via pagelayer_load_plugin
CVE-2023-49196
WordPress PageLayer Plugin < 1.7.8 is vulnerable to Cross Site Scripting (XSS)
WordPress PageLayer Plugin < 1.7.7 is vulnerable to Cross Site Scripting (XSS)
WordPress PageLayer Plugin < 1.7.7 is vulnerable to Cross Site Scripting (XSS)
PageLayer <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Pagelayer < 1.3.5 - Multiple Reflected Cross-Site Scripting (XSS)
WordPress PageLayer plugin <= 1.3.4 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2020-35947
CVE-2020-35944
CVE-2020-36384
CVE-2020-36383