Description
The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This bypasses both the WordPress core kses-on-save filter and the plugin's own wp_kses_post() call, because entity-encoded script tags are treated as inert text by kses but are decoded into live HTML by the subsequent html_entity_decode() call in CopyrightBlock::render_template().
Published: 2026-09-18
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting enabling arbitrary script execution in browsers
Action: Patch
AI Analysis

Impact

The Kubio AI Page Builder plugin stores user input through the kubio/copyright block without proper sanitization. An authenticated contributor or higher can inject HTML that contains entity‑encoded script tags. These tags slip through WordPress’s kses‑on‑save filter and the plugin’s wp_kses_post() call because they are decoded later by html_entity_decode(), turning inert text into executable code. When a page renders, the malicious script runs in the viewers’ browsers, potentially compromising session data, defacing content, or exfiltrating sensitive information. The vulnerability does not provide direct server‑side code execution; it is limited to the client side.

Affected Systems

WordPress sites that use the Kubio AI Page Builder plugin version 2.8.4 or earlier. The vendor is extendthemes and the product name is Kubio AI Page Builder. Only versions up to and including 2.8.4 are affected, as newer releases have remedied the issue.

Risk and Exploitability

The CVSS score of 6.4 places the flaw in the moderate range. Its EPSS score is below 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, meaning no known widespread attacks are documented. The attack vector requires an authenticated contributor to submit a malicious block; an attacker would then need a user to visit the edited page for the injected script to execute. Because of these constraints, the overall risk is moderate but non‑negligible for sites that allow contributors to edit content.

Generated by OpenCVE AI on September 19, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kubio AI Page Builder to the latest version (≥ 2.8.5) or apply any vendor‑supplied patch that removes the unchecked entity decoding.
  • If an upgrade cannot be performed immediately, remove or disable the kubio/copyright block for all contributor roles to prevent the store of malicious content.
  • Enable site‑wide content sanitization (for example, using a security plugin that filters legacy HTML or limits allowed tags) to block execution of injected scripts.

Generated by OpenCVE AI on September 19, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Extendthemes
Extendthemes kubio Ai Page Builder
Wordpress
Wordpress wordpress
Vendors & Products Extendthemes
Extendthemes kubio Ai Page Builder
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This bypasses both the WordPress core kses-on-save filter and the plugin's own wp_kses_post() call, because entity-encoded script tags are treated as inert text by kses but are decoded into live HTML by the subsequent html_entity_decode() call in CopyrightBlock::render_template().
Title Kubio AI Page Builder <= 2.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via kubio/copyright Block Content
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Extendthemes Kubio Ai Page Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T11:29:01.464Z

Reserved: 2026-07-02T14:33:10.545Z

Link: CVE-2026-14472

cve-icon Vulnrichment

Updated: 2026-09-18T11:28:57.728Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T08:16:59.567

Modified: 2026-09-18T13:23:37.403

Link: CVE-2026-14472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')