CVE-2024-2127: Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2127?
CVE-2024-2127 has been classified with a high severity due to its potential for Stored Cross-Site Scripting.
How do I fix CVE-2024-2127?
To fix CVE-2024-2127, update the Pagelayer plugin to the latest version beyond 1.8.3 where the vulnerability has been addressed.
Who is affected by CVE-2024-2127?
CVE-2024-2127 affects any WordPress site using the Pagelayer plugin version 1.8.3 or earlier.
What type of vulnerability is CVE-2024-2127?
CVE-2024-2127 is a stored cross-site scripting (XSS) vulnerability.
Can an attacker exploit CVE-2024-2127 remotely?
Yes, an authenticated attacker can exploit CVE-2024-2127 remotely to execute malicious scripts.