The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is disallowed, such as in multi-site WordPress configurations.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 22 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-22T17:24:53.316Z
Reserved: 2023-09-22T15:11:21.835Z
Link: CVE-2023-5124
Updated: 2024-08-02T07:44:53.790Z
Status : Modified
Published: 2024-01-29T15:15:09.100
Modified: 2025-05-22T18:15:31.467
Link: CVE-2023-5124
No data.
OpenCVE Enrichment
No data.
Weaknesses