Impact
The vulnerable Kubio AI Page Builder plugin stores unsanitized content from the 'comment' parameter directly into page output, allowing an attacker to embed arbitrary JavaScript. Because the injection is stored, any user who views the affected page will execute the malicious script. This stored cross‑site scripting can lead to phishing, credential theft, or defacement. The weakness is a classic input validation flaw consistent with CWE‑79.
Affected Systems
All releases of the Kubio AI Page Builder plugin distributed by Extend Themes up to and including version 2.9.2 are affected. The vulnerability appears in the comment handling routines within the plugin's core files.
Risk and Exploitability
The CVSS score of 7.2 reflects a high severity for unauthenticated stored XSS, while the absence of an EPSS score and KEV listing suggests that exploitation is currently neither widespread nor documented in known intrusion campaigns. An attacker only needs to supply a crafted comment, which is typically accessible via the public interface of the plugin. Once embedded, the script executes each time any user loads the affected page, giving the attacker persistent, cross‑site access.
OpenCVE Enrichment