Impact
The Kubio AI Page Builder plugin allows an unauthenticated user to submit comment content that bypasses the plugin’s HTML filtering. The filter, which is only meant for the editor context, is applied to user‑supplied data, permitting the stored insertion of malicious markup. When a site visitor or an administrator later loads the page containing that content, the browser executes the stored script. This vulnerability can result in session hijacking, phishing, or other client‑side attacks against anyone who views the affected page.
Affected Systems
WordPress sites running the Kubio AI Page Builder plugin version 2.9.3 or earlier are affected. The vulnerability is present in all releases before that specific version.
Risk and Exploitability
Because the flaw is a stored XSS, any user who can view the compromised content will be impacted. The attack requires no authentication; any visitor or administrator who views the page is at risk. Although there is no EPSS score, the nature of the vulnerability suggests a high likelihood of exploitation in practice, especially on sites that permit unauthenticated comment posting. The issue is not currently listed in the CISA KEV catalog, but the severity of XSS warrants immediate attention.
OpenCVE Enrichment