CVE · Medium

CVE-2025-12366 — Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12366 Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.6 Authorization Bypass Through User-Controlled Key Medium 4.3 < 2.0.6 2.0.6 2025-11-12

CVE-2025-12366

The Pagelayer plugin for WordPress contains an authentication bypass vulnerability in versions up to 2.0.5, which allows authorized users with elevated privileges to manipulate sensitive media assets owned by others through the pagelayer_replace_page function due to inadequate key verification. This flaw can be exploited by attackers who have been granted Author-level access or higher, enabling them to replace files intended for other users, including administrators.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.