Impact
The Kubio AI Page Builder plugin stores user input through the kubio/copyright block without proper sanitization. An authenticated contributor or higher can inject HTML that contains entity‑encoded script tags. These tags slip through WordPress’s kses‑on‑save filter and the plugin’s wp_kses_post() call because they are decoded later by html_entity_decode(), turning inert text into executable code. When a page renders, the malicious script runs in the viewers’ browsers, potentially compromising session data, defacing content, or exfiltrating sensitive information. The vulnerability does not provide direct server‑side code execution; it is limited to the client side.
Affected Systems
WordPress sites that use the Kubio AI Page Builder plugin version 2.8.4 or earlier. The vendor is extendthemes and the product name is Kubio AI Page Builder. Only versions up to and including 2.8.4 are affected, as newer releases have remedied the issue.
Risk and Exploitability
The CVSS score of 6.4 places the flaw in the moderate range. Its EPSS score is below 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, meaning no known widespread attacks are documented. The attack vector requires an authenticated contributor to submit a malicious block; an attacker would then need a user to visit the edited page for the injected script to execute. Because of these constraints, the overall risk is moderate but non‑negligible for sites that allow contributors to edit content.
OpenCVE Enrichment