← WordPress Vulnerabilities
WordPress security by component

Codeless Page Builder

Codeless Page Builder is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: codeless-page-builder

CVE-2026-15234: Codeless Page Builder tag attributes let Contributors store JavaScript

Codeless Page Builder through 1.1.4 uses an unsanitized shortcode attribute as an HTML tag name while rendering content. A Contributor-or-higher user can supply a crafted tag value that breaks the intended markup and injects HTML and JavaScript, which executes for an Administrator or other user who views the affected content. The record does not disclose the shortcode name, attribute name, renderer function or exact payload encoding.

PublishedAug 01, 2026
Safe version guidanceSee mitigation notes
Safe version
Aug 01, 2026 CVE-2026-15234
Codeless Page Builder tag attributes let Contributors store JavaScript
Codeless Page Builder through 1.1.4 uses an unsanitized shortcode attribute as an HTML tag name while rendering content. A Contributor-or-higher user can supply a crafted tag value that breaks the intended markup and injects HTML and JavaScript, which executes for an Administrator or other user who views the affected content. The record does not disclose the shortcode name, attribute name, renderer function or exact payload encoding.
See mitigation notes
CVEPending
NVDPending