What is CVE-2026-15234?
CVE-2026-15234 affects the 'Codeless Page Builder' WordPress plugin up to version 1.1.4. It fails to sanitize a shortcode attribute before using it as an HTML tag name, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that execute in other users' sessions. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-15234 'Codeless Page Builder' WordPress plaginində aşkarlanıb. 1.1.4 versiyasına qədər plagin qısa kod atributunu HTML teq adı kimi istifadə etməzdən əvvəl sanitizasiya etmir, bu da contributor və yuxarı səviyyəli istifadəçilərə ixtiyari HTML və JavaScript kodu inyeksiya etməyə imkan verir. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Who can exploit the CVE-2026-15234 vulnerability?
This vulnerability can be exploited by users with contributor-level access and above on the WordPress site.
What should be done to mitigate the CVE-2026-15234 vulnerability?
To mitigate the vulnerability, it is recommended to update the 'Codeless Page Builder' plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.