CVE-2024-2127
- EPSS 0.08%
- Veröffentlicht 07.03.2024 20:15:50
- Zuletzt bearbeitet 14.02.2025 17:28:36
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping...
CVE-2023-7115
- EPSS 0.19%
- Veröffentlicht 27.02.2024 09:15:37
- Zuletzt bearbeitet 27.03.2025 15:15:48
The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability ...
CVE-2024-1590
- EPSS 0.16%
- Veröffentlicht 23.02.2024 10:15:07
- Zuletzt bearbeitet 28.01.2025 17:32:02
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output...
CVE-2023-5124
- EPSS 0.13%
- Veröffentlicht 29.01.2024 15:15:09
- Zuletzt bearbeitet 22.05.2025 18:15:31
The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is disallowed, such as in multi-sit...
CVE-2023-6738
- EPSS 0.1%
- Veröffentlicht 04.01.2024 04:15:09
- Zuletzt bearbeitet 21.11.2024 08:44:27
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, ...
CVE-2023-5087
- EPSS 0.24%
- Veröffentlicht 16.10.2023 20:15:17
- Zuletzt bearbeitet 23.04.2025 17:16:49
The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.
CVE-2023-4687
- EPSS 0.55%
- Veröffentlicht 16.10.2023 20:15:16
- Zuletzt bearbeitet 23.04.2025 17:16:46
The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.
CVE-2020-36384
- EPSS 0.21%
- Veröffentlicht 07.06.2021 11:15:10
- Zuletzt bearbeitet 21.11.2024 05:29:22
PageLayer before 1.3.5 allows reflected XSS via color settings.
CVE-2020-36383
- EPSS 0.21%
- Veröffentlicht 07.06.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 05:29:22
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
CVE-2020-35944
- EPSS 0.21%
- Veröffentlicht 01.01.2021 04:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:34
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.