
CVE-2026-2509 The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and… https://www.cve.org/CVERecord?id=CVE-2026-2509
Post summary
The post announces CVE-2026-2509, revealing a stored XSS flaw in the Pagelayer WordPress plugin's Button widget, with no mention of PoCs, exploits, patches, or active attacks.
