Pagelayer
by WordPress
Source repositories
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4687 | 0.00 | — | 0.00 | Oct 16, 2023 | The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts. | |||
| CVE-2023-5087 | 0.00 | — | 0.00 | Oct 16, 2023 | The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code. | |||
| CVE-2020-36383 | 0.00 | — | 0.01 | Jun 7, 2021 | PageLayer before 1.3.5 allows reflected XSS via the font-size parameter. | |||
| CVE-2020-36384 | 0.00 | — | 0.01 | Jun 7, 2021 | PageLayer before 1.3.5 allows reflected XSS via color settings. | |||
| CVE-2020-35944 | 0.00 | — | 0.01 | Jan 1, 2021 | An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS. | |||
| CVE-2020-35947 | 0.00 | — | 0.01 | Jan 1, 2021 | An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of… |
- CVE-2023-4687Oct 16, 2023risk 0.00cvss —epss 0.00
The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.
- CVE-2023-5087Oct 16, 2023risk 0.00cvss —epss 0.00
The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.
- CVE-2020-36383Jun 7, 2021risk 0.00cvss —epss 0.01
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
- CVE-2020-36384Jun 7, 2021risk 0.00cvss —epss 0.01
PageLayer before 1.3.5 allows reflected XSS via color settings.
- CVE-2020-35944Jan 1, 2021risk 0.00cvss —epss 0.01
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.
- CVE-2020-35947Jan 1, 2021risk 0.00cvss —epss 0.01
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of…
Page 2 of 2