CVE-2020-35944: Pagelayer

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.

Affected products

  • Pagelayer Pagelayer: before 1.1.2 (fixed in 1.1.2)

Published 2021-01-01. Last modified 2026-06-17.