CVE · Medium

CVE-2024-30465 — Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.8.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-30465 Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.8.2 Missing Authorization Medium 6.5 < 1.8.2 1.8.2 2024-03-28

CVE-2024-30465

The PageLayer WordPress plugin contained a broken access control vulnerability prior to version 1.8.2 that allowed unprivileged users to perform actions normally restricted to higher-privilege accounts due to missing authorization and authentication checks. Researcher Rafie Muhammad identified and disclosed this issue, which has been patched in version 1.8.2 and later. Users should update their installations to the fixed version to prevent potential exploitation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.