Page Builder: Pagelayer – Drag and Drop website builder
pagelayer · eklenti
Page Builder: Pagelayer – Drag and Drop website builder için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
19 bilinen açık
3 kayıt giriş yapmadan sömürülebilir · son kayıt 13 Haz 2026
wordpress.org'da yayında · son sürüm 2.2.2 · son güncelleme 24 Eyl 2026 · 400 bin+ kurulum
wordpress.org durumu 2 Eki 2026 tarihinde kontrol edildi
Güvenlik açıkları
- Yüksek 8.8
CVE-2024-30465giriş gerekir≤ 1.8.1
WordPress PageLayer plugin <= 1.8.1 - Broken Access Control vulnerability
- Orta 6.5
CVE-2025-24573giriş gerekir≤ 1.9.4
WordPress Pagelayer plugin <= 1.9.4 - Cross Site Scripting (XSS) vulnerability
- Orta 6.4
CVE-2026-3297katılımcı+≤ 2.0.9
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block
- Orta 6.4
CVE-2026-2509katılımcı+≤ 2.0.8
Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes
- Orta 6.4
CVE-2024-13427katılımcı+≤ 2.0.0
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link
- Orta 5.4
CVE-2024-2504katılımcı+≤ 1.8.4
Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes
- Orta 5.4
CVE-2024-2127katılımcı+≤ 1.8.3
Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes
- Orta 5.4
CVE-2024-1590katılımcı+≤ 1.8.2
Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button
- Orta 5.4
CVE-2023-6738katılımcı+≤ 1.7.8
PageLayer <= 1.7.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields
- Orta 5.3
CVE-2026-2442kimlik doğrulamasız≤ 2.0.7
Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'
- Orta 4.8
CVE-2024-43972yüksek yetki≤ 1.8.7
WordPress Page Builder: Pagelayer – Drag and Drop website builder plugin <= 1.8.7 - Cross Site Scripting (XSS) vulnerability
- Orta 4.7
CVE-2025-4223kimlik doğrulamasız · tıklama gerekir≤ 2.0.0
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter
- Orta 4.3
CVE-2025-1926kimlik doğrulamasız · tıklama gerekir≤ 1.9.8
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification
- Orta 4.3
CVE-2026-39469giriş gerekir≤ 2.0.8
WordPress PageLayer plugin <= 2.0.8 - Sensitive Data Exposure vulnerability
- Orta 4.3
CVE-2023-49196giriş gerekir≤ 1.7.7
WordPress Pagelayer plugin <= 1.7.7 - Broken Access Control vulnerability
- Orta 4.3
CVE-2026-2470katılımcı+≤ 2.0.9
Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'
- Orta 4.3
CVE-2025-12366yazar+≤ 2.0.5
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference
- Orta 4.3
CVE-2025-2104katılımcı+≤ 1.9.8
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication
- Orta 4.3
CVE-2024-13430katılımcı+≤ 1.9.8
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode
Yetki etiketi kaydın kendi metninden okunur (ör. “abone+”: abone ve üstü roller). Metin rol söylemiyorsa CVSS'e göre “giriş gerekir” ya da “yüksek yetki” yazılır; rol adı uydurulmaz. “Tıklama gerekir”: saldırı, oturumu açık birinin bağlantıya tıklamasına bağlı (CSRF, yansıyan XSS).