RULE(RULE ID:324131)

Rule General Information
Release Date: 2020-01-19
Rule Name: Wordpress Page Layout Builder Plugin Reflected Cross Site Scripting Vulnerability (CVE-2016-1000141)
Severity:
CVE ID:
Rule Protection Details
Description: Reflected XSS in wordpress plugin page-layout-builder v1.9.3
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Others
Reference: SecurityFocusBID:93804
http://www.vapidlabs.com/wp/wp_advisory.php?v=358
https://wordpress.org/plugins/page-layout-builder
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://wordpress.org/plugins/page-layout-builder/