The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever [truncated]
CVE-2026-2470 is an Incorrect Authorization vulnerability in the Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress. The vulnerability affects all versions up to, and including, 2.0.9. The issue arises from the pagelayer_save_content AJAX handler, which allows users with basic post-edit capability to persist pagelayer_contact_templates metadata on posts they can edit, including p [truncated]
The CVE-2026-2509 vulnerability is a Stored Cross-Site Scripting issue in the Pagelayer plugin for WordPress. This vulnerability affects all versions up to, and including, 2.0.8. The issue arises from an incomplete event handler blocklist in the 'pagelayer_xss_content' XSS filtering function, which fails to block all event handlers. This allows authenticated attackers with Contributor-level access and abo [truncated]
CVE-2026-39469 is a MEDIUM-severity vulnerability in PageLayer, a WordPress plugin. It allows attackers to retrieve embedded sensitive data. The issue affects PageLayer versions from n/a through 2.0.8. This type of vulnerability could lead to unauthorized access to sensitive information, potentially impacting confidentiality. Users should review the official CVE record and NVD details for further information.