WordPress security by component
Codeless Page Builder
Plugin description
Codeless Page Builder is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
codeless-page-builderLatest vulnerability
CVE-2026-15234: Codeless Page Builder tag attributes let Contributors store JavaScript
Codeless Page Builder through 1.1.4 uses an unsanitized shortcode attribute as an HTML tag name while rendering content. A Contributor-or-higher user can supply a crafted tag value that breaks the intended markup and injects HTML and JavaScript, which executes for an Administrator or other user who views the affected content. The record does not disclose the shortcode name, attribute name, renderer function or exact payload encoding.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-15234
Codeless Page Builder tag attributes let Contributors store JavaScript
Codeless Page Builder through 1.1.4 uses an unsanitized shortcode attribute as an HTML tag name while rendering content. A Contributor-or-higher user can supply a crafted tag value that breaks the intended markup and injects HTML and JavaScript, which executes for an Administrator or other user who views the affected content. The record does not disclose the shortcode name, attribute name, renderer function or exact payload encoding.
|
See mitigation notes |
CVEPending
NVDPending
|