Page Builder: Pagelayer – Drag and Drop website builder

Explore Page Builder: Pagelayer – Drag and Drop website builder vulnerabilities across all versions. Currently tracking 30 known vulnerabilities, including severity, impact, and patch status.

01234567891028.05.2020Today28.05.20207.4Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Missing Authorization to Cross-Site Scripting CVSS 7.4 · 28.05.20208.8Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Cross-Site Request Forgery to Cross-Site Scripting CVSS 8.8 · 28.05.202010.12.20206.1Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via font-size CVSS 6.1 · 10.12.20206.1Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via Color Settings CVSS 6.1 · 10.12.202013.09.20236.4PageLayer <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 13.09.202325.09.20237.2Page Builder: Pagelayer – Drag and Drop website builder <= 1.7.6 - Missing Authorization to Stored Cross-Site Scripting CVSS 7.2 · 25.09.20236.4Page Builder: Pagelayer <= 1.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via Header/Footer CVSS 6.4 · 25.09.202301.12.20235.3PageLayer <= 1.7.7 - Cross-Site Request Forgery via pagelayer_load_plugin CVSS 5.3 · 01.12.202324.12.20234.4Page Builder: Pagelayer <= 1.7.9 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 24.12.202303.01.20245.4PageLayer <= 1.7.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields CVSS 5.4 · 03.01.202431.01.20244.4Pagelayer <= 1.7.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via Header/Footer code CVSS 4.4 · 31.01.202422.02.20244.6Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button CVSS 4.6 · 22.02.202407.03.20246.4Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes CVSS 6.4 · 07.03.202421.03.20246.4Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes CVSS 6.4 · 21.03.202428.03.20244.3PageLayer <= 1.8.1 - Missing Authorization CVSS 4.3 · 28.03.202428.07.20244.4Page Builder: Pagelayer <= 1.8.7 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 28.07.202428.08.20244.4PageLayer <= 1.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 28.08.202404.09.20244.4Page Builder: Pagelayer <= 1.8.9 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 04.09.202424.01.20256.4PageLayer <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 24.01.202509.03.20254.3Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification CVSS 4.3 · 09.03.202511.03.20254.3Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode CVSS 4.3 · 11.03.202512.03.20254.3Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication CVSS 4.3 · 12.03.202523.05.20256.4Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link CVSS 6.4 · 23.05.20254.7Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter CVSS 4.7 · 23.05.202512.11.20254.3Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference CVSS 4.3 · 12.11.202512.03.20264.3PageLayer <= 2.0.8 - Authenticated (Contributor+) Information Exposure CVSS 4.3 · 12.03.202627.03.20265.3Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' CVSS 5.3 · 27.03.202607.04.20266.4Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes CVSS 6.4 · 07.04.202612.06.20266.4Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block CVSS 6.4 · 12.06.20264.3Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts' CVSS 4.3 · 12.06.2026

Strategic Overview

Avg CVSSMedium
5.5/ 10
Patch Coverage100%
Open

0

Fixed

30

Get automatic notifications for all Page Builder: Pagelayer – Drag and Drop website builder vulnerabilities before they are exploited.

Vulnerability Records

30 records
2026-06-12 19:20CVE-2026-2470
4.3
Medium
Drew Webber (mcdruid)Yes
2026-06-12 19:06CVE-2026-3297
6.4
Medium
Athiwat Tiprasaharn (Jitlada)Yes
2026-04-07 00:00CVE-2026-2509
6.4
Medium
Athiwat Tiprasaharn (Jitlada)Yes
2026-03-27 20:45CVE-2026-2442
5.3
Medium
Drew Webber (mcdruid)Yes
2026-03-12 00:00CVE-2026-39469
4.3
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2025-11-12 15:20CVE-2025-12366
4.3
Medium
Athiwat Tiprasaharn (Jitlada)Yes
2025-05-23 15:53CVE-2025-4223
4.7
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2025-05-23 00:00CVE-2024-13427
6.4
Medium
zer0gh0stYes
2025-03-12 00:00CVE-2025-2104
4.3
Medium
Brian Sans-Souci (liardom)Yes
2025-03-11 00:00CVE-2024-13430
4.3
Medium
NishivYes
Showing 1–10 of 30 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C