CVE-2025-2104

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayer_save_content() function in all versions up to, and including, 1.9.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to bypass post moderation and publish posts to the site.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pagelayer:pagelayer:*:*:*:*:*:wordpress:*:*

History

26 May 2025, 02:13

Type Values Removed Values Added
CPE cpe:2.3:a:pagelayer:pagelayer:*:*:*:*:*:wordpress:*:*
First Time Pagelayer
Pagelayer pagelayer
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3253356%40pagelayer&new=3253356%40pagelayer&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3253356%40pagelayer&new=3253356%40pagelayer&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/2e3897fb-0f40-4111-8a7d-60415e1f9f96?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/2e3897fb-0f40-4111-8a7d-60415e1f9f96?source=cve - Third Party Advisory
Summary
  • (es) El complemento Page Builder: Pagelayer – Drag and Drop website builder para WordPress es vulnerable a la publicación no autorizada de entradas debido a una validación insuficiente de la función pagelayer_save_content() en todas las versiones hasta la 1.9.8 incluida. Esto permite que atacantes autenticados, con acceso de Ccolaborador o superior, eludan la moderación de entradas y publiquen entradas en el sitio.

13 Mar 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-13 05:15

Updated : 2025-05-26 02:13


NVD link : CVE-2025-2104

Mitre link : CVE-2025-2104

CVE.ORG link : CVE-2025-2104


JSON object : View

Products Affected

pagelayer

  • pagelayer
CWE
CWE-862

Missing Authorization