CVE-2026-15234
Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.
| Vendor | unknown |
| Product | codeless page builder |
| Published | Aug 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown codeless page builder
Be the first to know when new unknown vulnerabilities affecting unknown codeless page builder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Codeless Page Builder
0 โค 1.1.4
References
Credits
testoun WPScan