CVE-2024-13430: Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayerbuilderpostsshortcode' function due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private posts that they should not have access to.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13430?
CVE-2024-13430 has been classified as a medium severity vulnerability due to information exposure risks.
How does CVE-2024-13430 affect users?
CVE-2024-13430 can lead to unauthorized access to information from WordPress posts due to insufficient restrictions.
How do I fix CVE-2024-13430?
To mitigate CVE-2024-13430, users should update the Pagelayer plugin to version 1.9.9 or later.
What versions of Pagelayer are affected by CVE-2024-13430?
CVE-2024-13430 affects all versions of Pagelayer up to and including 1.9.8.
Is there a workaround for CVE-2024-13430 while waiting for a fix?
There are no known workarounds for CVE-2024-13430, so users should update to the latest version as soon as possible.