Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown
CVE-2023-5087
Disclosure Date: October 16, 2023 (last updated October 21, 2023)
The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.
0
Attacker Value
Unknown
CVE-2023-4687
Disclosure Date: October 16, 2023 (last updated October 21, 2023)
The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.
0
Attacker Value
Unknown
CVE-2020-36383
Disclosure Date: June 07, 2021 (last updated February 22, 2025)
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
0
Attacker Value
Unknown
CVE-2020-36384
Disclosure Date: June 07, 2021 (last updated February 22, 2025)
PageLayer before 1.3.5 allows reflected XSS via color settings.
0
Attacker Value
Unknown
CVE-2020-35947
Disclosure Date: January 01, 2021 (last updated February 22, 2025)
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.
0
Attacker Value
Unknown
CVE-2020-35944
Disclosure Date: January 01, 2021 (last updated February 22, 2025)
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.
0