CVE-2024-1590: Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1590?
CVE-2024-1590 is classified as a high-severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-1590?
To fix CVE-2024-1590, update the Pagelayer plugin to version 1.8.3 or later.
Which versions of Pagelayer are affected by CVE-2024-1590?
CVE-2024-1590 affects all versions of the Pagelayer plugin up to and including version 1.8.2.
What type of vulnerability is CVE-2024-1590?
CVE-2024-1590 is a stored cross-site scripting (XSS) vulnerability.
How does CVE-2024-1590 impact WordPress sites?
CVE-2024-1590 can allow attackers to inject malicious scripts into webpages, potentially compromising the security of WordPress sites using the vulnerable Pagelayer plugin.