CVE · Medium

CVE-2025-24573 — Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.9.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-24573 Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.9.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 1.9.5 1.9.5 2025-01-24

CVE-2025-24573

The PageLayer plugin for WordPress contains a security flaw in versions 1.9.4 and earlier, where input validation is inadequate, allowing malicious code to be embedded within the application's output. This vulnerability enables authorized users with contributor-level permissions or higher to introduce executable scripts that will run whenever an affected page is accessed by another user.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.