Vulnerabilities > Pagelayer > Pagelayer > 1.8.9

DATE CVE VULNERABILITY TITLE RISK
2025-03-13 CVE-2025-2104 Missing Authorization vulnerability in Pagelayer
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayer_save_content() function in all versions up to, and including, 1.9.8.
network
low complexity
pagelayer CWE-862
4.3
2025-03-12 CVE-2024-13430 Improper Access Control vulnerability in Pagelayer
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient restrictions on which posts can be included.
network
low complexity
pagelayer CWE-284
4.3
2025-03-10 CVE-2025-1926 Cross-Site Request Forgery (CSRF) vulnerability in Pagelayer
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8.
network
low complexity
pagelayer CWE-352
4.3