CVE · Medium

CVE-2026-2470 — Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-2470 Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.1.0 Incorrect Authorization Medium 4.3 < 2.1.0 2.1.0 2026-06-12

CVE-2026-2470

The Pagelayer plugin for WordPress has a security flaw that allows attackers with contributor-level access and above to set up custom contact form templates that can be used by anyone to send emails, even if they're not logged in. This is because the plugin doesn't properly check who can access and edit these templates, and the templates can be triggered by anyone through a special URL parameter. The vulnerability can be exploited by chaining it with another known issue to gain even more control over email behavior.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.