Access violation vulnerability in Page Builder: Pagelayer – Drag and Drop website builder 1.7.7

The Page Builder: Pagelayer plugin for WordPress is vulnerable to an attack called Cross-Site Request Forgery. This means that versions of the plugin up to and including 1.7.7 are affected. This attack happens because the plugin does not have the correct measures in place to stop unauthenticated attackers from disabling the “getting started” promo by sending a forged request to the website administrator.

Detected in:

Page Builder: Pagelayer – Drag and Drop website builder fixed vulnerable versions: >= * <= 1.7.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.