WordPress · Codeless Page Builder · CVE-2026-15234
**Name of the Vulnerable Software and Affected Versions**
Codeless Page Builder versions prior to 1.1.5
**Description**
Insufficient sanitization and validation of a shortcode attribute allows users with contributor-level access and above to inject arbitrary HTML and JavaScript. This occurs when the attribute is used as an HTML tag name during content rendering, leading to stored Cross-Site Scripting (XSS), where the injected code executes in the session of higher-privileged users, such as administrators, who view the affected content.
**Recommendations**
Update Codeless Page Builder to version 1.1.5 or later.