Description
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.
Published: 2026-10-03
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Patch Immediately
AI Analysis

Impact

The Kubio AI Page Builder WordPress plugin before version 2.9.3 contains a stored cross‑site scripting vulnerability in the image gallery item URL attribute. Because the plugin does not validate the URI scheme of a user‑supplied value before rendering it as a link target, any contributor or higher level user can embed a malicious payload that will execute in the browser of anyone who follows the link, including administrators previewing unpublished submissions.

Affected Systems

The flaw affects any WordPress site that has Kubio AI Page Builder installed with a version older than 2.9.3. Users granted the contributor role or higher privileges in the plugin have the ability to add image gallery items, making them able to inject the malicious payload.

Risk and Exploitability

The vulnerability allows stored XSS that can impact users with any level of access—including site administrators—whenever they click the compromised link. Because the attacker only needs to create or edit an image gallery item via the standard plugin interface, the exploitation barrier is low. The issue is not listed in the CISA KEV catalog and no EPSS score is available, but the lack of input validation combined with broad contributor privileges suggests a high likelihood of exploitation in a reasonably active WordPress community.

Generated by OpenCVE AI on October 3, 2026 at 07:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kubio AI Page Builder to version 2.9.3 or later to apply the fix that validates URL schemes.
  • If an upgrade cannot be performed immediately, restrict users with the contributor role from adding or editing image gallery items until the patch is applied.
  • Scan all existing image gallery items for suspicious or externally hosted URLs and remove or sanitize any that include dangerous schemes such as javascript:, data:, or vbscript.
  • Implement or enable a site‑wide security plugin that blocks or sanitizes non‑HTTP/HTTPS URI schemes in rendered content as an additional safeguard.

Generated by OpenCVE AI on October 3, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.
Title Kubio AI Page Builder < 2.9.3 - Contributor+ Stored XSS via Image Gallery Item URL Attribute
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T15:12:21.821Z

Reserved: 2026-09-10T07:42:36.477Z

Link: CVE-2026-88782

cve-icon Vulnrichment

Updated: 2026-10-03T15:01:26.891Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:44.740

Modified: 2026-10-03T16:16:40.277

Link: CVE-2026-88782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T07:30:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')