Pagelayer is a page-building and website-creation platform whose vulnerability exposure centers on web-application-layer weaknesses recurrent across its core product. The durable signal reflects the platform's role in user-generated content and form handling, with repeated instances of cross-site scripting, cross-site request forgery, and authorization and input-validation gaps that are characteristic of web builders where user input flows directly into rendering contexts. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pagelayer over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35944HIGH An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS. | Jan 1, 2021 | 8.8 | 26 | NO | NO |
CVE-2024-30465HIGH Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1. | Jun 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2020-35947HIGH An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed | Jan 1, 2021 | 7.4 | 23 | NO | NO |
CVE-2023-4687MEDIUM The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts. | Oct 16, 2023 | 6.1 | 19 | NO | NO |
CVE-2020-36384MEDIUM PageLayer before 1.3.5 allows reflected XSS via color settings. | Jun 7, 2021 | 6.1 | 19 | NO | NO |
CVE-2020-36383MEDIUM PageLayer before 1.3.5 allows reflected XSS via the font-size parameter. | Jun 7, 2021 | 6.1 | 19 | NO | NO |
CVE-2025-24573MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softaculous PageLayer pagelayer allows DOM-Based XSS.This issue affects PageLa | Jan 24, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-2504MEDIUM The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and in | Apr 9, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-5124MEDIUM The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or foot | Jan 29, 2024 | 4.8 | 18 | NO | NO |
CVE-2023-5087MEDIUM The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or | Oct 16, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pagelayer.
Media articles that mention a CVE ID that affects a product developed by Pagelayer — matched by CVE ID, not by vendor name.