CVE-2026-85678
Received Received - Intake

Stored XSS in AI Builder WordPress Plugin

Vulnerability report for CVE-2026-85678, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: WPScan

Description

The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of anyone who views the post, including the editor or administrator who reviews it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ai_builder plugin to 2.7.8 (exc)
ai_builder plugin From 2.4.1 (inc) to 2.7.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in the AI Builder WordPress plugin versions 2.4.1 to 2.7.7. Users with contributor-level access or higher can inject malicious JavaScript into posts. The plugin fails to sanitize this custom JavaScript before rendering it in a script tag on the front end, causing the code to execute in the browsers of anyone viewing the post, including editors or administrators.

Detection Guidance

To detect this vulnerability, check the version of the AI Builder WordPress plugin installed on your system. If the version is between 2.4.1 and 2.7.7, it is vulnerable. You can use WordPress commands like 'wp plugin list' or check the plugin details in the WordPress admin panel.

Impact Analysis

Attackers with contributor access or higher could steal cookies, session tokens, or sensitive data from other users viewing the post. They could also perform actions on behalf of users, deface the website, or redirect visitors to malicious sites. Administrators reviewing posts are also at risk of account compromise.

Compliance Impact

This vulnerability could lead to data breaches, exposing personal or sensitive data, which may violate GDPR and HIPAA requirements. Organizations could face fines or penalties for failing to protect user data adequately. The risk of unauthorized access to protected health information or personal data increases with this flaw.

Mitigation Strategies

Immediately update the AI Builder plugin to version 2.7.8 or later to patch the vulnerability. If updating is not possible, consider disabling the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85678. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart