Plugin Vulnerability Hub
Plugin 26 known issues Latest disclosed Mar 27, 2026

Page Builder: Pagelayer – Drag and Drop website builder Vulnerabilities

Review known vulnerability records for the WordPress plugin Page Builder: Pagelayer – Drag and Drop website builder (`pagelayer`), including severity, CVE references, affected versions, and patch status.

Known Records
26
High or Critical
3
Linked CVEs
25
Last Updated
Mar 27, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Page Builder: Pagelayer – Drag and Drop website builder so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
26 records include a published patch path.
Severity Mix
0 critical and 3 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Page Builder: Pagelayer – Drag and Drop website builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-2442
Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.0.7. This is due to the contact form handler performing placeholder substitution...

Published
Mar 27, 2026
Patched Release
2.0.8
Affected Versions
Versions up to 2.0.7
Next Step
Update to 2.0.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-12366
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.5 via the pagelayer_replace_page function due to missing validation on a user controlled key. This makes it...

Published
Nov 12, 2025
Patched Release
2.0.6
Affected Versions
Versions up to 2.0.5
Next Step
Update to 2.0.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-4223
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘login_url’ parameter in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it pos...

Published
May 23, 2025
Patched Release
2.0.1
Affected Versions
Versions up to 2.0.0
Next Step
Update to 2.0.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13427
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied att...

Published
May 23, 2025
Patched Release
2.0.1
Affected Versions
Versions up to 2.0.0
Next Step
Update to 2.0.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-2104
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayer_save_content() function in all versions up to, and including, 1.9.8. This makes it possible for authenti...

Published
Mar 12, 2025
Patched Release
2.0.0
Affected Versions
Versions up to 1.9.8
Next Step
Update to 2.0.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13430
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can be included....

Published
Mar 11, 2025
Patched Release
1.9.9
Affected Versions
Versions up to 1.9.8
Next Step
Update to 1.9.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-1926
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the pagelayer_save_post function. This makes it possib...

Published
Mar 09, 2025
Patched Release
1.9.9
Affected Versions
Versions up to 1.9.8
Next Step
Update to 1.9.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-24573
PageLayer <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inje...

Published
Jan 24, 2025
Patched Release
1.9.5
Affected Versions
Versions up to 1.9.4
Next Step
Update to 1.9.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-8618
Page Builder: Pagelayer <= 1.8.9 - Authenticated (Admin+) Stored Cross-Site Scripting

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping. This makes it possible for auth...

Published
Sep 04, 2024
Patched Release
1.9.0
Affected Versions
Versions up to 1.8.9
Next Step
Update to 1.9.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-43972
PageLayer <= 1.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to in...

Published
Aug 28, 2024
Patched Release
1.8.8
Affected Versions
Versions up to 1.8.7
Next Step
Update to 1.8.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-8426
Page Builder: Pagelayer <= 1.8.7 - Authenticated (Admin+) Stored Cross-Site Scripting

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for auth...

Published
Jul 28, 2024
Patched Release
1.8.8
Affected Versions
Versions up to 1.8.7
Next Step
Update to 1.8.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-30465
PageLayer <= 1.8.1 - Missing Authorization

The PageLayer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the pagelayer_trash_post() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers, with contributor-level access and ab...

Published
Mar 28, 2024
Patched Release
1.8.2
Affected Versions
Versions up to 1.8.1
Next Step
Update to 1.8.2 or newer if supported.