CVE-2026-2442

Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.0.7. This is due to the contact form handler performing placeholder substitution on attacker-controlled form fields and then passing the resulting values into email headers without removing CR/LF characters. This makes it possible for unauthenticated attackers to inject arbitrary email headers (for example Bcc / Cc) and abuse form email delivery via the 'email' parameter granted they can target a contact form configured to use placeholders in mail template headers.


We have discovered 10,373 live websites that are affected by CVE-2026-2442.

Run a Free Instant Scan




Affected Software

Product  Pagelayer
Category Wordpress Plugins
Vulnerable Domains10,373 live websites (71% of Pagelayer install base)
Vulnerable Versions
  • from 0 through 2.0.7
Vulnerable Versions Count84 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')



Details

  • Published - Mar 28, 2026
  • Updated - Apr 8, 2026

Credits

  • Drew Webber (finder)

Website Distribution by Country

Number of websites using CVE-2026-2442
United States2,957 websites



GB653 websites
Italy592 websites
South Africa424 websites
Brazil401 websites
France386 websites
Indonesia369 websites
Canada357 websites
Germany338 websites
Romania334 websites

Website Distribution by TLD

Number of websites using CVE-2026-2442
.com4,371 websites
.org637 websites
.it377 websites
.com.br366 websites
.net333 websites
.co.uk246 websites
.ca171 websites
.pl169 websites
.nl168 websites
.com.au129 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-2442

Top websites that are affected by CVE-2026-2442. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.****.edu United States***,***
****.ca Canada***,***
*********.com Portugal***,***
**********.com GB***,***
*********.com United States***,***
******.net Indonesia***,***
******************.net Canada***,***
**********.com United States***,***
**************.com United States***,***
******.org United States***,***
See full domain list

FAQ

CVE-2026-2442 is Improper Neutralization of CRLF Sequences ('CRLF Injection') in Pagelayer
A total of 10,373 websites have been identified as vulnerable to CVE-2026-2442, based on global website indexing conducted by WebTechSurvey.
The Pagelayer is affected by the CVE-2026-2442 vulnerability.
Pagelayer versions up to and including 2.0.7 are vulnerable to CVE-2026-2442.