Insecure Direct Object Reference in Pagelayer Drag and Drop Website Builder for WordPress
CVE-2025-12366

4.3MEDIUM

What is CVE-2025-12366?

The Pagelayer Drag and Drop website builder plugin for WordPress is vulnerable to an Insecure Direct Object Reference due to inadequate validation of user-controlled keys in the pagelayer_replace_page function. This security flaw allows authenticated attackers, who possess Author-level access or higher, to tamper with media files belonging to other users, including those of administrators. This vulnerability poses a significant risk as it could lead to unauthorized modifications, data loss, and overall disruption of web content management.

Affected Version(s)

Page Builder: Pagelayer – Drag and Drop website builder * <= 2.0.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
.
CVE-2025-12366 : Insecure Direct Object Reference in Pagelayer Drag and Drop Website Builder for WordPress