HIGH
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress
Published Jan 1, 2021
7.4
HIGHCVSS 3.1
EPSS 1.10%
Description
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-23530 Advisory
- https://wpscan.com/vulnerability/10239 x_refsource_MISCExploitThird Party Advisory
- https://www.wordfence.com/blog/2020/05/high-severity-vulnerabilities-in-pagelayer-plugin-affect-over-200000-wordpress-sites/ x_refsource_MISCExploitPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-23530 | Advisory | |
| https://wpscan.com/vulnerability/10239 | x_refsource_MISCExploitThird Party Advisory | |
| https://www.wordfence.com/blog/2020/05/high-severity-vulnerabilities-in-pagelayer-plugin-affect-over-200000-wordpress-sites/ | x_refsource_MISCExploitPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 1, 2021
Updated Aug 4, 2024
Reserved Jan 1, 2021
Link CVE-2020-35947
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data