4.3
CVSSv3

CVE-2025-2104

CVSSv4: NA | CVSSv3: 4.3 | CVSSv2: NA | VMScore: 530 | EPSS: 0.00029 | KEV: Not Included
Published: 13/03/2025 Updated: 13/03/2025

Vulnerability Summary

WordPress Pagelayer Plugin Post Publication Bypass Vulnerability in Versions 1.9.8 and Below

The Page Builder: Pagelayer WordPress plugin, which provides a drag and drop website building interface, contains a security vulnerability in its pagelayer_save_content() function. This vulnerability affects all plugin versions up to and including 1.9.8, allowing authenticated attackers with Contributor-level access or higher to bypass post moderation controls and publish posts directly to the site without proper authorization.