CVE-2025-2104: Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayersavecontent() function in all versions up to, and including, 1.9.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to bypass post moderation and publish posts to the site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/page-builder-pagelayerto a version that resolves this vulnerability.Fixed in 1.9.9 - Compensating control
Reduce the ability of non-admin roles to publish content by restricting Contributor+ accounts’ posting permissions until the plugin is updated (vulnerable up to and including 1.9.8).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2104?
The severity of CVE-2025-2104 is considered high due to unauthorized post publication risks.
How do I fix CVE-2025-2104?
To fix CVE-2025-2104, update the Pagelayer plugin to version 1.9.9 or later.
What versions are affected by CVE-2025-2104?
CVE-2025-2104 affects all versions of Pagelayer up to and including 1.9.8.
Who is affected by CVE-2025-2104?
Users of the Pagelayer Drag and Drop website builder plugin for WordPress are affected by CVE-2025-2104.
What kind of attack is possible with CVE-2025-2104?
CVE-2025-2104 allows attackers to publish posts without proper authorization due to insufficient validation.