The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.0.7. This is due to the contact form handler performing placeholder substitution on attacker-controlled form fields and then passing the resulting values into email headers without removing CR/LF characters. This makes it possible for unauthenticated attackers to inject arbitrary email headers (for example Bcc / Cc) and abuse form email delivery via the 'email' parameter granted they can target a contact form configured to use placeholders in mail template headers.
We have discovered 10,373 live websites that are affected by CVE-2026-2442.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 10,373 live websites (71% of Pagelayer install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 84 versions ( 98% of all versions) |
| 2,957 websites | |
| 653 websites | |
| 592 websites | |
| 424 websites | |
| 401 websites | |
| 386 websites | |
| 369 websites | |
| 357 websites | |
| 338 websites | |
| 334 websites |
| .com | 4,371 websites |
| .org | 637 websites |
| .it | 377 websites |
| .com.br | 366 websites |
| .net | 333 websites |
| .co.uk | 246 websites |
| .ca | 171 websites |
| .pl | 169 websites |
| .nl | 168 websites |
| .com.au | 129 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.****.edu | ***,*** | ||
| ****.ca | ***,*** | ||
| *********.com | ***,*** | ||
| **********.com | ***,*** | ||
| *********.com | ***,*** | ||
| ******.net | ***,*** | ||
| ******************.net | ***,*** | ||
| **********.com | ***,*** | ||
| **************.com | ***,*** | ||
| ******.org | ***,*** |
FAQ