WordPress Plugin Vulnerabilities

Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute

Description

The plugin does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
testoun
Submitter
testoun
Verified
Yes

Timeline

Publicly Published
2026-07-17 (about 16 days ago)
Added
2026-07-10 (about 23 days ago)
Last Updated
2026-07-10 (about 23 days ago)

Other