PT-2026-49084 · WordPress · Pagelayer
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Page Builder: Pagelayer versions prior to 2.1.0
Description
Incorrect Authorization exists in the Page Builder: Pagelayer plugin. The
pagelayer save content AJAX handler allows users with basic post-edit capabilities to persist pagelayer contact templates metadata on posts they can edit, including pending posts. Subsequently, the unauthenticated 'pagelayer contact submit' endpoint consumes this metadata using user-controlled post or form identifiers without enforcing a privileged or published-context boundary. This allows authenticated attackers with Contributor-level access or higher to configure arbitrary contact-form mail templates, which can then be triggered via unauthenticated form submissions through the contacts parameter. While this template feature is typically managed via the Pagelayer Pro UI, the vulnerable backend trust path remains present.Recommendations
Update the plugin to a version later than 2.0.9.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pagelayer