Impact
Extend Themes Kubio AI Website Builder contains an improper input validation flaw that can be exploited to cause a denial of service. The weakness is a classic untrusted input processing issue (CWE-20) leading to application unresponsiveness or crash when malformed data is received.
Affected Systems
The affected product is the WordPress Kubio AI Website Builder plugin supplied by Extend Themes. Versions prior to 2.9.1 are vulnerable and require remediation.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score is not available, meaning current exploitation likelihood information is lacking. The vulnerability is not listed in the CISA KEV catalog. Due to the absence of explicit attack vector data, the most probable scenario is that an attacker must persuade or trick a user into submitting malformed input through the plugin’s interface. Mitigation through a quick patch is recommended to reduce the risk of a service disruption.
OpenCVE Enrichment