---
id: CVE-2026-15234
title: >-
  The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or
  validate a shortcode attribute before using it as an HTML tag name when
  rendering content, allowing users with contributor-level access and above to
  inject arb…
summary: >-
  The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or
  validate a shortcode attribute before using it as an HTML tag name when
  rendering content, allowing users with contributor-level access and above to
  inject arb…
severity: none
published: '2026-08-01'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15234'
references:
  - url: 'https://wpscan.com/vulnerability/519a69d5-ab6f-449a-ab78-78b68598d37f/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00226
epssPercentile: 0.11893
ingestedAt: '2026-08-02T05:17:47.594Z'
---

## Overview

The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
