CVE Database /
CVE-2020-35947
CVE · High
CVE-2020-35947 — Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.1.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-35947
|
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.1.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.4
|
< 1.1.2
|
1.1.2 |
2020-05-28 |
—
|
CVE-2020-35947
The PageLayer plugin before version 1.1.2 contained multiple AJAX endpoints that failed to properly verify user permissions, enabling any authenticated user to execute these actions. The vulnerability stemmed from relying solely on nonces for authorization while exposing those nonces in publicly accessible pages. The most severe consequence involved the pagelayer_save_content function, which could be exploited to alter page content and inject malicious scripts via cross-site scripting attacks.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings