CVE-2023-5124: PageLayer < 1.8.0 - Author+ Stored XSS
The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfilteredhtml is disallowed, such as in multi-site WordPress configurations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5124?
CVE-2023-5124 has a high severity due to its potential for allowing unfiltered JavaScript insertion by administrators.
How do I fix CVE-2023-5124?
To fix CVE-2023-5124, update the Pagelayer WordPress plugin to version 1.8.0 or later.
Who is affected by CVE-2023-5124?
CVE-2023-5124 affects all installations of the Pagelayer WordPress plugin prior to version 1.8.0.
What kind of attack can CVE-2023-5124 facilitate?
CVE-2023-5124 can facilitate cross-site scripting (XSS) attacks through the insertion of malicious JavaScript code.
Is CVE-2023-5124 relevant for multi-site WordPress configurations?
Yes, CVE-2023-5124 is particularly relevant for multi-site WordPress configurations where unfiltered_html is disallowed.