PT-2021-11879 · WordPress · Pagelayer

Published

2021-01-01

·

Updated

2021-07-21

·

CVE-2020-35947

CVSS v3.1

7.4

High

VectorAC:L/AV:N/A:L/C:L/I:L/PR:L/S:C/UI:N
Name of the Vulnerable Software and Affected Versions: PageLayer plugin versions prior to 1.1.2
Description: An issue was discovered in the PageLayer plugin for WordPress, where nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer save content function that allowed pages to be modified and allowed XSS to occur.
Recommendations: For versions prior to 1.1.2, update to version 1.1.2 or later to resolve the issue. As a temporary workaround, consider disabling the pagelayer save content function until a patch is available. Restrict access to the AJAX action endpoints to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35947

Affected Products

Pagelayer