The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesnt prevent attackers with author privileges and higher from inserting malicious JavaScript inside a posts header or footer code.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Pagelayer |
Pagelayer |
* |
1.7.8 (excluding) |
References