CVE-2025-24573: WordPress Pagelayer plugin <= 1.9.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softaculous PageLayer pagelayer allows DOM-Based XSS.This issue affects PageLayer: from n/a through <= 1.9.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24573?
CVE-2025-24573 is classified as a high severity vulnerability due to its potential for exploiting Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-24573?
To fix CVE-2025-24573, upgrade PageLayer to version 1.9.4 or later as recommended by the vendor.
What software is affected by CVE-2025-24573?
CVE-2025-24573 affects PageLayer versions from n/a through 1.9.4 and the WordPress Pagelayer plugin up to version 1.9.4.
What type of vulnerability is CVE-2025-24573?
CVE-2025-24573 is a DOM-Based Cross-site Scripting (XSS) vulnerability, which allows attackers to execute scripts in the user’s browser.
Who is the vendor for CVE-2025-24573?
The vendor associated with CVE-2025-24573 is Pagelayer Team, responsible for the PageLayer software.