PT-2026-49084 · WordPress · Pagelayer

·

CVE-2026-2470

·

Published

2026-06-13

·

Updated

2026-06-16

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Page Builder: Pagelayer versions prior to 2.1.0
Description Incorrect Authorization exists in the Page Builder: Pagelayer plugin. The pagelayer save content AJAX handler allows users with basic post-edit capabilities to persist pagelayer contact templates metadata on posts they can edit, including pending posts. Subsequently, the unauthenticated 'pagelayer contact submit' endpoint consumes this metadata using user-controlled post or form identifiers without enforcing a privileged or published-context boundary. This allows authenticated attackers with Contributor-level access or higher to configure arbitrary contact-form mail templates, which can then be triggered via unauthenticated form submissions through the contacts parameter. While this template feature is typically managed via the Pagelayer Pro UI, the vulnerable backend trust path remains present.
Recommendations Update the plugin to a version later than 2.0.9.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2470

Affected Products

Pagelayer