CVE-2023-7115: PageLayer < 1.8.1 - Admin+ Stored XSS
The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7115?
CVE-2023-7115 has a high severity rating due to the potential for Stored Cross-Site Scripting (XSS) attacks by privileged users.
How do I fix CVE-2023-7115?
To fix CVE-2023-7115, update the Pagelayer WordPress plugin to version 1.8.1 or later.
Who is affected by CVE-2023-7115?
CVE-2023-7115 affects users of the Pagelayer plugin on WordPress installations prior to version 1.8.1.
What types of attacks can be performed using CVE-2023-7115?
CVE-2023-7115 can be exploited for Stored Cross-Site Scripting attacks, allowing malicious scripts to be executed within user browsers.
What is the impact of CVE-2023-7115?
The impact of CVE-2023-7115 includes the potential for unauthorized data access and control over affected websites by executing malicious scripts.