WordPress Pagelayer Plugin Post Publication Bypass Vulnerability in Versions 1.9.8 and Below
The Page Builder: Pagelayer WordPress plugin, which provides a drag and drop website building interface, contains a security vulnerability in its pagelayer_save_content() function. This vulnerability affects all plugin versions up to and including 1.9.8, allowing authenticated attackers with Contributor-level access or higher to bypass post moderation controls and publish posts directly to the site without proper authorization.