First published: Mon Oct 16 2023(Updated: )
The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pagelayer | <1.7.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-5087.
The affected software is the Pagelayer WordPress plugin before version 1.7.8.
The severity of CVE-2023-5087 is medium (5.4).
CVE-2023-5087 allows attackers with author privileges and higher to insert malicious JavaScript inside a post's header or footer code.
To fix CVE-2023-5087, update the Pagelayer WordPress plugin to version 1.7.8 or newer.