PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15234 Codeless CVE debrief

The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.

Vendor
Codeless
Product
Codeless Page Builder
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-01
Original CVE updated
2026-08-01
Advisory published
2026-08-01
Advisory updated
2026-08-01

Who should care

Administrators and users with contributor-level access and above who use the Codeless Page Builder WordPress plugin should review and update to version 1.1.5 or later. Additionally, security teams and vulnerability management teams should assess the risk and prioritize patching or mitigation efforts for affected deployments. Platform operators and security personnel responsible for WordPress installations should also be aware of this vulnerability and take necessary actions to protect their environments. This includes reviewing system logs for potential exploitation attempts and ensuring that all users with contributor-level access and above are trusted and monitored. Furthermore, organizations using the affected plugin should consider implementing compensating controls, such as restricting contributor-level access to trusted users and monitoring for suspicious activity on affected systems. They should also track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory management and source tracking can help identify and prioritize affected systems for remediation. Rollback change windows and source tracking can aid in verifying the effectiveness of mitigations and detecting potential regressions. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts and anomalous behavior. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their WordPress installations from potential attacks. Security teams should also consider reviewing compensating controls for exposed systems while remediation is scheduled and verified, and checking relevant monitoring, detection, and logs for exposed assets that need extra review. This will help ensure that the vulnerability is properly mitigated and that the risk is minimized. Overall, a comprehensive approach to vulnerability management, including prompt patching, compensating controls, and ongoing monitoring, is essential to protecting against this and other vulnerabilities. By prioritizing these efforts, organizations can reduce the risk of exploitation and protect their 3

Technical summary

The Codeless Page Builder WordPress plugin through 1.1.4 is vulnerable to arbitrary HTML and JavaScript injection due to insufficient sanitization of shortcode attributes. This allows users with contributor-level access and above to inject malicious code that can be executed by higher-privileged users, such as administrators, who view the content. The plugin does not properly validate or sanitize the shortcode attribute before using it as an HTML tag name when rendering content.

Defensive priority

Administrators and users with contributor-level access and above should review and update the Codeless Page Builder WordPress plugin to version 1.1.5 or later.

Recommended defensive actions

  • Update Codeless Page Builder WordPress plugin to version 1.1.5 or later
  • Restrict contributor-level access and above to trusted users
  • Monitor for suspicious activity on affected systems
  • Review system logs for potential exploitation attempts
  • Implement compensating controls, such as restricting contributor-level access to trusted users and monitoring for suspicious activity on affected systems
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Verify affected versions (Codeless Page Builder WordPress plugin through 1.1.4) and user roles (contributor-level access and above) for accurate risk assessment

Evidence notes

The evidence for this CVE is limited; verify affected versions (Codeless Page Builder WordPress plugin through 1.1.4) and user roles (contributor-level access and above) for accurate risk assessment. Defenders should verify system configurations, user access controls, and monitor for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T07:16:31.163Z and has not been modified since then.