Skip to main content

Software intelligence

Pagelayer vulnerabilities

30 tracked advisories · slug pagelayer

Important: Pagelayer appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works

Tracked advisories

30

Latest advisory

12 June 2026

CISA KEV matches

0

In this WordPress feed

WordPress slug

pagelayer

Plugin

What this means for Pagelayer

This catalog lists 30 known advisories affecting Pagelayer. The most recent was published on 12 June 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.

Latest issues

  • Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'

    This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.

    Published 12 June 2026

  • Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block

    May allow attackers to run scripts in visitors' browsers or hijack admin sessions.

    Published 12 June 2026

  • Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes

    May allow attackers to run scripts in visitors' browsers or hijack admin sessions.

    Published 7 April 2026

Vulnerability types

  • Cross-site scripting21
  • CSRF2

Authentication (inferred from titles)

  • Unauthenticated1
  • Authenticated20
  • Unspecified9

Advisory history

Known Pagelayer advisories published by month.

All advisories

1–15 of 30

1 / 2

Check whether your installed version is affected

SiteRespond Defence matches your installed Pagelayer version against this catalog when the Defence plugin is connected to your WordPress site.