{"id":"CVE-2026-15234","title":"The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arb…","summary":"The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arb…","severity":"none","published":"2026-08-01","updated":"2026-08-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15234","references":[{"url":"https://wpscan.com/vulnerability/519a69d5-ab6f-449a-ab78-78b68598d37f/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00129,"epssPercentile":0.02912,"ingestedAt":"2026-08-02T05:17:47.594Z","slug":"CVE-2026-15234","body":"## Overview\n\nThe Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}