CVE-2026-88782
Received Received - Intake

Stored XSS in Kubio AI Page Builder WordPress Plugin

Vulnerability report for CVE-2026-88782, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: WPScan

Description

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kubio ai_page_builder to 2.9.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the Kubio AI Page Builder WordPress plugin before version 2.9.3. It allows users with contributor roles or higher to inject malicious scripts via the URL attribute of an image gallery item. The plugin does not validate the URI scheme of user-supplied input before rendering it as a link target, enabling stored XSS attacks.

Detection Guidance

Check the installed version of the Kubio AI Page Builder plugin. If it is below 2.9.3, the system is vulnerable. Logs may show attempts to inject malicious scripts via the URL attribute of image gallery items.

Impact Analysis

The vulnerability allows attackers to execute malicious scripts in the browsers of anyone accessing the infected link, including administrators previewing unpublished content. This could lead to unauthorized actions, data theft, or session hijacking on the affected WordPress site.

Compliance Impact

This vulnerability could compromise user data privacy, potentially violating GDPR or HIPAA requirements for data protection and security. Unauthorized script execution may lead to data breaches or unauthorized access, triggering compliance violations and legal consequences.

Mitigation Strategies

Update the Kubio AI Page Builder plugin to version 2.9.3 or later immediately. Remove or restrict contributor-level access if not required. Monitor for suspicious activity in logs related to script injections.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88782. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart