Description
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before 2.9.3's own script later executes in the browser of any visitor, or of an administrator reviewing the still-unapproved submission.
Published: 2026-10-03
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Upgrade
AI Analysis

Impact

The Kubio AI Page Builder plugin allows an unauthenticated user to submit comment content that bypasses the plugin’s HTML filtering. The filter, which is only meant for the editor context, is applied to user‑supplied data, permitting the stored insertion of malicious markup. When a site visitor or an administrator later loads the page containing that content, the browser executes the stored script. This vulnerability can result in session hijacking, phishing, or other client‑side attacks against anyone who views the affected page.

Affected Systems

WordPress sites running the Kubio AI Page Builder plugin version 2.9.3 or earlier are affected. The vulnerability is present in all releases before that specific version.

Risk and Exploitability

Because the flaw is a stored XSS, any user who can view the compromised content will be impacted. The attack requires no authentication; any visitor or administrator who views the page is at risk. Although there is no EPSS score, the nature of the vulnerability suggests a high likelihood of exploitation in practice, especially on sites that permit unauthenticated comment posting. The issue is not currently listed in the CISA KEV catalog, but the severity of XSS warrants immediate attention.

Generated by OpenCVE AI on October 3, 2026 at 07:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kubio AI Page Builder to version 2.9.3 or later
  • If an upgrade is not immediately possible, delete or sanitize any stored comments containing unexpected HTML markup
  • Disable comment posting for unauthenticated users or enforce manual moderation until the plugin is updated

Generated by OpenCVE AI on October 3, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before 2.9.3's own script later executes in the browser of any visitor, or of an administrator reviewing the still-unapproved submission.
Title Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T15:12:21.692Z

Reserved: 2026-09-10T07:42:38.158Z

Link: CVE-2026-88783

cve-icon Vulnrichment

Updated: 2026-10-03T15:01:13.247Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:45.037

Modified: 2026-10-03T16:16:40.427

Link: CVE-2026-88783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T07:30:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')