Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 15 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 13 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Softaculous
Softaculous page Builder: Pagelayer – Drag And Drop Website Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Softaculous
Softaculous page Builder: Pagelayer – Drag And Drop Website Builder Wordpress Wordpress wordpress |
Sat, 13 Jun 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_save_content AJAX handler allowing users with basic post-edit capability to persist pagelayer_contact_templates metadata on posts they can edit (including pending posts), while the unauthenticated pagelayer_contact_submit endpoint later consumes that metadata by user-controlled post/form identifiers without enforcing a privileged or published-context boundary. This makes it possible for authenticated attackers, with Contributor-level access and above, to configure arbitrary contact-form mail templates that are usable through unauthenticated form submission via the contacts parameter. In typical deployments this template feature is configured via Pagelayer Pro UI; however, the vulnerable backend trust path is still present. This issue may be chained with CVE-2026-2442 to increase exploitability and attacker control over outbound email behavior. | |
| Title | Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts' | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-06-15T13:40:23.970Z
Reserved: 2026-02-13T14:37:26.487Z
Link: CVE-2026-2470
Updated: 2026-06-15T13:40:17.944Z
Status : Deferred
Published: 2026-06-13T08:16:12.030
Modified: 2026-06-15T20:42:32.707
Link: CVE-2026-2470
No data.
OpenCVE Enrichment
Updated: 2026-06-13T10:00:09Z