Information Exposure in Pagelayer Drag and Drop Website Builder Plugin for WordPress
CVE-2024-13430
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 March 2025
What is CVE-2024-13430?
The Pagelayer Drag and Drop website builder plugin for WordPress contains a vulnerability that allows authenticated attackers, with Contributor-level access and above, to exploit insufficient restrictions within the 'pagelayer_builder_posts_shortcode' function. This weakness permits these attackers to access and extract sensitive data from private posts that are not meant for their viewing, potentially leading to unauthorized data disclosure.
Affected Version(s)
Page Builder: Pagelayer – Drag and Drop website builder * <= 1.9.8