CVE-2026-15234 PUBLISHED

Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute

Assigner: WPScan
Reserved: 09.07.2026 Published: 01.08.2026 Updated: 01.08.2026

The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.

Product Status

Vendor Unknown
Product Codeless Page Builder
Versions Default: unknown
  • affected from 0 to 1.1.4 (incl.)

Credits

  • testoun finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE