Executive brief
Softaculous PageLayer, a popular drag-and-drop page builder plugin for WordPress, contains a security flaw that allows unauthorized users to access sensitive system information. An attacker with basic contributor-level access could view data that is normally restricted, potentially gaining insights into the site's configuration or internal structure. This information could be used to facilitate more advanced attacks against the website.
Technical details
Softaculous PageLayer (a WordPress plugin) is vulnerable to CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere. The vulnerability exists in versions up to and including 2.0.8. An attacker with 'Contributor' or higher privileges can exploit this flaw via the network to retrieve embedded sensitive data that should not be accessible to their role. The root cause involves improper access controls or insufficient sanitization of data spheres, allowing the leakage of system-level information. This issue was addressed in version 2.0.9.
Affected products
- Softaculous PageLayer <= 2.0.8
Timeline
- 2026-02-10: other: Vulnerability reported by researcher
- 2026-03-12: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published
- 2026-04-08: patched: Patch released in version 2.0.9