PT-2026-28338 · WordPress · Pagelayer

Drew Webber

·

Published

2026-03-28

·

Updated

2026-06-13

·

CVE-2026-2442

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Page Builder: Pagelayer versions up to and including 2.0.7
Description The Page Builder: Pagelayer WordPress plugin is susceptible to CRLF Injection due to improper handling of Carriage Return and Line Feed characters in the contact form handler. The plugin performs placeholder substitution on attacker-controlled form fields and passes the resulting values into email headers without removing CR/LF characters. This allows unauthenticated attackers to inject arbitrary email headers, such as Bcc or Cc, and potentially abuse form email delivery through the email parameter, provided they can target a contact form configured to use placeholders in mail template headers.
Recommendations Update Page Builder: Pagelayer to a version later than 2.0.7

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2442

Affected Products

Pagelayer