Impact
The Kubio AI Page Builder WordPress plugin before version 2.9.3 contains a stored cross‑site scripting vulnerability in the image gallery item URL attribute. Because the plugin does not validate the URI scheme of a user‑supplied value before rendering it as a link target, any contributor or higher level user can embed a malicious payload that will execute in the browser of anyone who follows the link, including administrators previewing unpublished submissions.
Affected Systems
The flaw affects any WordPress site that has Kubio AI Page Builder installed with a version older than 2.9.3. Users granted the contributor role or higher privileges in the plugin have the ability to add image gallery items, making them able to inject the malicious payload.
Risk and Exploitability
The vulnerability allows stored XSS that can impact users with any level of access—including site administrators—whenever they click the compromised link. Because the attacker only needs to create or edit an image gallery item via the standard plugin interface, the exploitation barrier is low. The issue is not listed in the CISA KEV catalog and no EPSS score is available, but the lack of input validation combined with broad contributor privileges suggests a high likelihood of exploitation in a reasonably active WordPress community.
OpenCVE Enrichment