Description
Improper input validation vulnerability in Extend Themes Kubio AI Website Builder.

This issue affects Kubio AI Website Builder: before 2.9.1.
Published: 2026-08-31
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Extend Themes Kubio AI Website Builder contains an improper input validation flaw that can be exploited to cause a denial of service. The weakness is a classic untrusted input processing issue (CWE-20) leading to application unresponsiveness or crash when malformed data is received.

Affected Systems

The affected product is the WordPress Kubio AI Website Builder plugin supplied by Extend Themes. Versions prior to 2.9.1 are vulnerable and require remediation.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score is not available, meaning current exploitation likelihood information is lacking. The vulnerability is not listed in the CISA KEV catalog. Due to the absence of explicit attack vector data, the most probable scenario is that an attacker must persuade or trick a user into submitting malformed input through the plugin’s interface. Mitigation through a quick patch is recommended to reduce the risk of a service disruption.

Generated by OpenCVE AI on August 31, 2026 at 17:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kubio AI Website Builder to version 2.9.1 or later.
  • If an upgrade cannot be applied immediately, temporarily disable the Kubio AI Website Builder plugin or enable maintenance mode to prevent further exploitation.
  • Monitor application logs for abnormal requests to the plugin endpoints and consider adding WAF rules to filter or block malformed input.

Generated by OpenCVE AI on August 31, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1.
Title WordPress Kubio AI Website Builder - Denial Of Service
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-08-31T16:14:52.669Z

Reserved: 2026-08-31T15:42:30.259Z

Link: CVE-2026-83492

cve-icon Vulnrichment

Updated: 2026-08-31T16:14:44.777Z

cve-icon NVD

Status : Received

Published: 2026-08-31T16:19:20.250

Modified: 2026-08-31T17:17:47.483

Link: CVE-2026-83492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T17:45:02Z

Weaknesses
  • CWE-20

    Improper Input Validation