Information Exposure in Pagelayer Drag and Drop Website Builder Plugin for WordPress
CVE-2024-13430

4.3MEDIUM

What is CVE-2024-13430?

The Pagelayer Drag and Drop website builder plugin for WordPress contains a vulnerability that allows authenticated attackers, with Contributor-level access and above, to exploit insufficient restrictions within the 'pagelayer_builder_posts_shortcode' function. This weakness permits these attackers to access and extract sensitive data from private posts that are not meant for their viewing, potentially leading to unauthorized data disclosure.

Affected Version(s)

Page Builder: Pagelayer – Drag and Drop website builder * <= 1.9.8

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nirmal
.