CVE-2026-2442Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.0.7. This is due to the contact form handler performing placeholder substitution on attacker-controlled form fields and then passing the resulting values into email headers without removing CR/LF characters. This makes it possible for unauthenticated attackers to inject arbitrary email headers (for example Bcc / Cc) and abuse form email delivery via the 'email' parameter granted they can target a contact form configured to use placeholders in mail template headers.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-28: 3Technical Details · 2026-03-28: 303-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2442 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2442 #CVE-2026-2442 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/iwnCHc72i4

    Post summary

    A new CVE, CVE‑2026‑2442, has been announced with a medium severity score of 5.3 affecting WordPress; only the NVD reference is provided, with no exploit, PoC, or patch information.

    0000034
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2442 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all ve… https://www.cve.org/CVERecord?id=CVE-2026-2442

    Post summary

    The CVE-2026-2442 record states that Pagelayer WordPress plugin is vulnerable to CRLF injection, providing the vulnerability type but no exploits, patches, or active use details.

    0000083
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2442 - Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' Intel Report: https://ift.tt/kgDxPuw

    Post summary

    A threat alert for CVE-2026-2442 affecting Pagelayer versions <= 2.0.7, describing a CRLF injection leading to unauthenticated email header injection; no PoC, exploit, or patch information is provided.

    0000013
    283 followersView on X

Explore more