CVE-2023-5087: PageLayer < 1.7.8 - Author+ Stored XSS
Published Oct 16, 2023
·Updated
The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.
Affected Software
1 affected component
PageLayer Pagelayer WordPress<1.7.8
Event History
Oct 16, 2023
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-5087.
2
What is the affected software?
The affected software is the Pagelayer WordPress plugin before version 1.7.8.
3
What is the severity of CVE-2023-5087?
The severity of CVE-2023-5087 is medium (5.4).
4
How does CVE-2023-5087 affect WordPress?
CVE-2023-5087 allows attackers with author privileges and higher to insert malicious JavaScript inside a post's header or footer code.
5
How can I fix CVE-2023-5087?
To fix CVE-2023-5087, update the Pagelayer WordPress plugin to version 1.7.8 or newer.