Page Builder: Pagelayer – Drag and Drop website builder

Vulnerabilities 33Slug pagelayerLatest version 2.1.0WordPress.org →

Minimum safe version

2.0.9

Update to 2.0.9 or later to address 33 fixable vulnerabilities

Latest available2.1.0
N/A
2026-04-07< 2.0.9

Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes

N/A
2026-03-27< 2.0.8

Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'

Medium 4.7
2025-05-24< 2.0.1

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter

Medium 4.8
2025-05-15< 1.9.0

Page Builder: Pagelayer <= 1.8.9 - Authenticated (Admin+) Stored Cross-Site Scripting

Medium 4.8
2025-05-15< 1.8.8

Page Builder: Pagelayer <= 1.8.7 - Authenticated (Admin+) Stored Cross-Site Scripting

Medium 4.3
2025-03-13< 2.0.0

Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication

Medium 4.3
2025-03-10< 1.9.9

Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification

Medium 4.8
2024-01-31< 1.8.0

Pagelayer <= 1.7.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via Header/Footer code

N/A
< 1.7.7

PageLayer &lt; 1.7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

N/A
2023-12-01< 1.7.8

PageLayer <= 1.7.7 - Cross-Site Request Forgery via pagelayer_load_plugin

N/A
2023-09-14< 1.7.7

WordPress PageLayer Plugin < 1.7.7 is vulnerable to Cross Site Scripting (XSS)

N/A
2023-09-13< 1.7.7

PageLayer <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

N/A
< 1.3.5

Pagelayer &lt; 1.3.5 - Multiple Reflected Cross-Site Scripting (XSS)

N/A
2020-12-10< 1.3.5

WordPress PageLayer plugin <= 1.3.4 - Reflected Cross-Site Scripting (XSS) vulnerability