The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesnt prevent attackers with author privileges and higher from inserting malicious JavaScript inside a posts header or footer code.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Pagelayer | Pagelayer | * | 1.7.8 (excluding) |
References