SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15234

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Codeless Page Builder WordPress plugin versions up to 1.1.4 is vulnerable due to improper sanitization of shortcode attributes, enabling users with contributor-level access or higher to inject arbitrary HTML and JavaScript. This can lead to session hijacking or other malicious actions affecting higher-privileged users, such as administrators, when they view the compromised content. WordPress site administrators and developers using this plugin should prioritize applying updates or implementing mitigations to safeguard against potential exploitation.

CVE
CVE-2026-15234
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%
WordPress Java

Original NVD Description

The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.