← Zurück zur CVE-Suche

CVE-2026-2442

Pagelayer

Beschreibung

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences (-CRLF Injection-) in all versions up to, and including, 2.0.7. This is due to the contact form handler performing placeholder substitution on attacker-controlled form fields and then passing the resulting values into email headers without removing CR/LF characters. This makes it possible for unauthenticated attackers to inject arbitrary email headers (for example Bcc / Cc) and abuse form email delivery via the -email- parameter granted they can target a contact form configured to use placeholders in mail template headers.

CVSS 5.3EPSS 0.297%Risiko 0.54
Quelle öffnen
Veröffentlicht
2026-03-28 10:16:30
Betroffene Versionen
<=2.0.7
Typ
Installed app
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N