
10/3/2025

10/3/2025
CVE-2025-1926: Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification
First published: Mon Mar 10 2025(Updated: )
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the pagelayer_save_post function. This makes it possible for unauthenticated attackers to modify post contents via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|
Pagelayer | <=1.9.8 | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is the severity of CVE-2025-1926?
CVE-2025-1926 is considered a moderate risk vulnerability due to the potential for Cross-Site Request Forgery affecting WordPress sites.
How do I fix CVE-2025-1926?
To fix CVE-2025-1926, update the Pagelayer plugin to version 1.9.9 or later, where the nonce validation issue has been resolved.
Which versions of the Pagelayer plugin are affected by CVE-2025-1926?
CVE-2025-1926 affects all versions of the Pagelayer plugin up to and including version 1.9.8.
What does CVE-2025-1926 allow attackers to do?
CVE-2025-1926 allows attackers to perform unauthorized actions on behalf of users due to missing nonce validation in the plugin.
Is CVE-2025-1926 specific to WordPress?
Yes, CVE-2025-1926 specifically affects the Pagelayer website builder plugin for WordPress.
- collector/mitre-cve
- source/MITRE
- agent/weakness
- agent/references
- agent/type
- agent/title
- agent/first-publish-date
- agent/description
- agent/softwarecombine
- agent/guess-ai
- agent/software-canonical-lookup
- agent/software-canonical-lookup-request
- collector/nvd-api
- source/NVD
- agent/last-modified-date
- agent/source
- agent/severity
- agent/author
- agent/tags
- agent/event
- vendor/pagelayer
- canonical/pagelayer
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203