Junglewise Threat Intelligence

CVE-2026-3297: Pagelayer WordPress plugin stored XSS in Anchor block

CVE-2026-3297 · Severity: medium · CVSS 6.4 · Published 2026-06-13

Executive brief

Pagelayer is a popular WordPress plugin used to design websites using a drag-and-drop interface. A security flaw allows users with basic contributor-level access to embed malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The Pagelayer WordPress plugin (versions <= 2.0.9) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within the Anchor block component. An authenticated attacker with at least contributor-level privileges can inject arbitrary web scripts into the Anchor block. Because the plugin fails to properly neutralize this input, the script is stored on the server and executed in the context of a victim's browser session whenever they access the modified page. This vulnerability is tracked as CWE-79 and has been addressed in subsequent updates.

Affected products

  • Pagelayer Pagelayer – Drag and Drop website builder up to, and including, 2.0.9

Timeline

  • 2026-06-13: disclosed
  • 2026-06-13: advisory

References