Page Builder: Pagelayer – Drag and Drop website builder

Page Builder: Pagelayer – Drag and Drop website builder has 30 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2026; all 30 are fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 3 high. 2024 was the busiest year with 9 disclosures.

The most common weakness is Cross-Site Scripting, behind 18 of the records (60%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).

Every one of the 30 issues recorded for Page Builder: Pagelayer – Drag and Drop website builder has a vendor fix available, so running the current release closes all known holes.

18 independent researchers contributed these findings, most of them (3) reported by Athiwat Tiprasaharn (Jitlada). Page Builder: Pagelayer – Drag and Drop website builder is installed on roughly 400,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891008.04.2019Today28.05.20207.4Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Missing Authorization to Cross-Site Scripting CVSS 7.4 · 28.05.20208.8Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Cross-Site Request Forgery to Cross-Site Scripting CVSS 8.8 · 28.05.202010.12.20206.1Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via font-size CVSS 6.1 · 10.12.20206.1Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via Color Settings CVSS 6.1 · 10.12.202013.09.20236.4PageLayer <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 13.09.202325.09.20237.2Page Builder: Pagelayer – Drag and Drop website builder <= 1.7.6 - Missing Authorization to Stored Cross-Site Scripting CVSS 7.2 · 25.09.20236.4Page Builder: Pagelayer <= 1.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via Header/Footer CVSS 6.4 · 25.09.202301.12.20235.3PageLayer <= 1.7.7 - Cross-Site Request Forgery via pagelayer_load_plugin CVSS 5.3 · 01.12.202324.12.20234.4Page Builder: Pagelayer <= 1.7.9 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 24.12.202303.01.20245.4PageLayer <= 1.7.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields CVSS 5.4 · 03.01.202431.01.20244.4Pagelayer <= 1.7.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via Header/Footer code CVSS 4.4 · 31.01.202422.02.20244.6Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button CVSS 4.6 · 22.02.202407.03.20246.4Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes CVSS 6.4 · 07.03.202421.03.20246.4Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes CVSS 6.4 · 21.03.202428.03.20244.3PageLayer <= 1.8.1 - Missing Authorization CVSS 4.3 · 28.03.202428.07.20244.4Page Builder: Pagelayer <= 1.8.7 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 28.07.202428.08.20244.4PageLayer <= 1.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 28.08.202404.09.20244.4Page Builder: Pagelayer <= 1.8.9 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 04.09.202424.01.20256.4PageLayer <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 24.01.202509.03.20254.3Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification CVSS 4.3 · 09.03.202511.03.20254.3Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode CVSS 4.3 · 11.03.202512.03.20254.3Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication CVSS 4.3 · 12.03.202523.05.20256.4Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link CVSS 6.4 · 23.05.20254.7Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter CVSS 4.7 · 23.05.202512.11.20254.3Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference CVSS 4.3 · 12.11.202512.03.20264.3PageLayer <= 2.0.8 - Authenticated (Contributor+) Information Exposure CVSS 4.3 · 12.03.202627.03.20265.3Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' CVSS 5.3 · 27.03.202607.04.20266.4Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes CVSS 6.4 · 07.04.202612.06.20266.4Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block CVSS 6.4 · 12.06.20264.3Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts' CVSS 4.3 · 12.06.2026

Strategic Overview

Avg CVSSMedium
5.5/ 10
Patch Coverage100%
Open

0

Fixed

30

Get automatic notifications for all Page Builder: Pagelayer – Drag and Drop website builder vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2020-35944

Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Cross-Site Request Forgery to Cross-Site Scripting

Read the full analysis

Vulnerability Records

30 records
2026-06-12 19:20CVE-2026-2470
4.3
Medium
Drew Webber (mcdruid)Yes
2026-06-12 19:06CVE-2026-3297
6.4
Medium
Athiwat Tiprasaharn (Jitlada)Yes
2026-04-07 00:00CVE-2026-2509
6.4
Medium
Athiwat Tiprasaharn (Jitlada)Yes
2026-03-27 20:45CVE-2026-2442
5.3
Medium
Drew Webber (mcdruid)Yes
2026-03-12 00:00CVE-2026-39469
4.3
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2025-11-12 15:20CVE-2025-12366
4.3
Medium
Athiwat Tiprasaharn (Jitlada)Yes
2025-05-23 15:53CVE-2025-4223
4.7
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2025-05-23 00:00CVE-2024-13427
6.4
Medium
zer0gh0stYes
2025-03-12 00:00CVE-2025-2104
4.3
Medium
Brian Sans-Souci (liardom)Yes
2025-03-11 00:00CVE-2024-13430
4.3
Medium
NishivYes
Showing 1–10 of 30 reports
Page Builder: Pagelayer – Drag and Drop website builder banner
Latestv2.1.9

Page Builder: Pagelayer – Drag and Drop website builder

Softaculous

Author

Softaculous

3.9(103)
78/100
Last Updated
2026-09-02 (11d ago)
Active Installs
400,000+
Downloads
9,545,398
Requires WP
4.7+
Requires PHP
5.5+
Tested up to
WP 7.0.4
Created
2019-04-08 (8y ago)

Presenting you Pagelayer a WordPress Website builder. Whether you’re a beginner or a professional, Pagelayer is built for delivering the best designing experience and fast performance that you will fall in love with. Pagelayer is an awesome page builder that allows you to create and design your website instantly in the simplest way possible. Take control over your page content with the most advanced page builder plugin available. With Pagelayer, you can create just about everything ! Home Page | Support | Documents Gutenberg Editor Blocks Integration Pagelayer smoothly collaborates with the Gutenberg editor, ensuring it aligns seamlessly with WordPress’ built-in block editor. This means you can effortlessly blend Pagelayer’s advanced page-building tools with the user-friendly Gutenberg blocks, giving you the best of both worlds. Whether you fancy the straightforwardness of Gutenberg blocks or the sophistication of Pagelayer’s drag-and-drop editor, the decision is entirely yours. This compatibility grants you the flexibility to harness the strengths of both systems, resulting in unmatched design versatility for your WordPress website. Explore the synergy of Pagelayer and Gutenberg, unlocking a new level of creativity for your web projects. Next generation Drag & Drop Editor Now making your imagined website designs is as simple as just a few drag and drop made possible only with Pagelayer. A next-generation page builder with so many features and functionality and as easy as a piece of cake without the need of technical knowledge. Widgets for every design Thinking if the design in your mind is possible 🤔? Yes! it is now possible with Pagelayer. We have a large number of widgets (100+) to choose and design from, be it a blog, portfolio, corporate, e-commerce or any other category. With Pagelayer everything is possible. To learn about widgets visit here. Stunning Experience with Real-Time Design Designing is no fun if we have to refresh the page to see the changes being applied😥. Say no to reloads. Pagelayer builder is a real-time builder so whenever you make changes on your page it gets updated instantly on the preview in the editor so you can check how the changes look. It helps you design your page quickly by saving your time. No more disjointed experience, build and edit everything right in front of your eyes. E-Commerce website designing Turn your website into an eCommerce machine with innovative tools and widgets to create an online shopping experience: product catalogs, product pages or shopping carts. Advanced In-line Editing Experience the all-new PEN editor a next-generation text editor. Simply click on any text and start typing edit the existing text or add your custom text. A variety of header and text options enhance your experience as well. Responsiveness for all device With Pagelayer responsive design is now made easy no coding, no hassle just a few tweaks and your website is ready to render as per your desired setting on any kind of device. Manage responsiveness for typography, color, padding, and all settings for tablet and mobile. Cloning made easy Now save time by just a click of a mouse, need to clone a section? or a page? or a post? no worries Pagelayer got you covered. Leave duplicating to Pagelayer the all-new advanced real-time builder. 30+ Free Widgets and adding more Row Columns Title Rich Text Quote List Icon Badge Tooltip Image Image Slider Video Grid Gallery Button Tabs Accordion Collapse Image Box Icon Box Space Embed Shortcodes Counter Google Maps Testimonial Progress Bars Color Block Alert Divider Social Profile Star Rating Anchor And counting… Unlock the BEST with Pagelayer PREMIUM The most powerful and professional website builder unlocks the beast with pro [features]{https://pagelayer.com/features/} that will improve your website performance and designing experience to the next level. Get access to more professional widgets, options, and tools to get recognized. ** There are many features to improve your website ** * Sticky header * Motion Effects * Mega Menu * Infinite Scroll * Call to Action * Contact Form * Image Hotspot * Table * Modal * Popup Builder * TimeLine * Slides * List of Premium widgets * Adding More…

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C