CVE-2023-4687: PageLayer < 1.7.7 - Unauthenticated Stored XSS
Published Oct 16, 2023
·Updated
The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.
Affected Software
1 affected component
PageLayer Pagelayer WordPress<1.7.7
Event History
Oct 16, 2023
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-4687.
2
What is the severity of CVE-2023-4687?
The severity of CVE-2023-4687 is medium with a CVSS score of 6.1.
3
How can an unauthenticated attacker exploit CVE-2023-4687?
An unauthenticated attacker can exploit CVE-2023-4687 by updating a post's header or footer code on scheduled posts.
4
What is the affected software for CVE-2023-4687?
The affected software for CVE-2023-4687 is the Page Builder: Pagelayer WordPress plugin before version 1.7.7.
5
How can I fix CVE-2023-4687?
To fix CVE-2023-4687, you should update the Page Builder: Pagelayer WordPress plugin to version 1.7.7 or later.