CVE-2025-4223: Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘loginurl’ parameter in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. A valid username/password pair needs to be supplied in order to be successfully exploited and any injected scripts will only execute in the context of that authenticated user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4223?
CVE-2025-4223 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting.
How do I fix CVE-2025-4223?
To fix CVE-2025-4223, users should update the Pagelayer plugin to version 2.0.1 or later immediately.
What versions of Pagelayer are affected by CVE-2025-4223?
CVE-2025-4223 affects all versions of Pagelayer up to and including 2.0.0.
What type of vulnerability is CVE-2025-4223?
CVE-2025-4223 is a reflected cross-site scripting vulnerability resulting from improper input sanitization.
Who is the vendor of the affected software for CVE-2025-4223?
The vendor of the affected software for CVE-2025-4223 is Pagelayer.