Pricing
Case studies
Login
Start trial
PageLayer
Softaculous
Developer
2.0.9
Latest version
400,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
24 patched
6 Mitigation rules
Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' vulnerability
<= 2.0.7
5 days ago
Admin+ Stored XSS vulnerability
< 1.8.8
31/12/2025
Authenticated (Author+) Insecure Direct Object Reference vulnerability
<= 2.0.5
12/11/2025
Reflected Cross-Site Scripting via login_url Parameter vulnerability
<= 2.0.0
23/05/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link vulnerability
<= 2.0.0
23/05/2025
Admin+ Stored XSS vulnerability
< 1.9.0
19/05/2025
Missing Authorization to Authenticated (Contributor+) Post Publication vulnerability
<= 1.9.8
12/03/2025
Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode vulnerability
<= 1.9.8
11/03/2025
Cross-Site Request Forgery (CSRF) To Post Contents Modification vulnerability
<= 1.9.8
10/03/2025
Cross Site Scripting (XSS) vulnerability
<= 1.9.4
24/01/2025
Cross Site Scripting (XSS) vulnerability
<= 1.8.7
28/08/2024
Broken Access Control vulnerability
<= 1.8.1
28/03/2024
Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes vulnerability
<= 1.8.4
22/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes vulnerability
<= 1.8.3
07/03/2024
Admin+ Stored XSS vulnerability
< 1.8.1
27/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Button vulnerability
<= 1.8.2
23/02/2024
Author+ Stored XSS vulnerability
<= 1.7.9
31/01/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via meta fields vulnerability
<= 1.7.8
31/01/2024
Broken Access Control vulnerability
<= 1.7.7
01/12/2023
Author+ Stored XSS vulnerability
< 1.7.8
17/10/2023
Unauthenticated Stored XSS vulnerability
< 1.7.7
17/10/2023
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
< 1.7.7
14/09/2023
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.3.4
10/12/2020
Unprotected AJAX and Nonce Disclosure to Stored Cross-Site Scripting (XSS)
<= 1.1.1
28/05/2020