High severity7.4NVD Advisory· Published Jan 1, 2021· Updated Jun 17, 2026
CVE-2020-35947
CVE-2020-35947
Description
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.
Affected products
3- WordPress/PageLayer plugindescription
Patches
Vulnerability mechanics
References
2- wpscan.com/vulnerability/10239nvdExploitThird Party Advisory
- www.wordfence.com/blog/2020/05/high-severity-vulnerabilities-in-pagelayer-plugin-affect-over-200000-wordpress-sites/nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.