CVE Database /
CVE-2025-12366
CVE · Medium
CVE-2025-12366 — Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12366
|
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.6 |
Authorization Bypass Through User-Controlled Key |
Medium
4.3
|
< 2.0.6
|
2.0.6 |
2025-11-12 |
—
|
CVE-2025-12366
The Pagelayer plugin for WordPress contains an authentication bypass vulnerability in versions up to 2.0.5, which allows authorized users with elevated privileges to manipulate sensitive media assets owned by others through the pagelayer_replace_page function due to inadequate key verification. This flaw can be exploited by attackers who have been granted Author-level access or higher, enabling them to replace files intended for other users, including administrators.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings