Input validation vulnerability in Page Builder: Pagelayer – Drag and Drop website builder 1.8.4

The Page Builder, called Pagelayer, is a plugin for WordPress that helps users build their website by dragging and dropping elements. However, it has a security vulnerability called Stored Cross-Site Scripting. This means that the ‘attr’ parameter, which allows users to add attributes to their pages, is not properly checked for harmful code and can be used by attackers. This can potentially harm users who visit the affected pages.

Detected in:

Page Builder: Pagelayer – Drag and Drop website builder fixed vulnerable versions: >= * <= 1.8.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.