PT-2026-104528 · WordPress · Kubio Ai Page Builder
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kubio AI Page Builder WordPress plugin versions prior to 2.9.3
Description
The plugin fails to restrict the expansion of allowed HTML elements to the editor context. Consequently, this expanded set of allowed elements is applied to content submitted by unauthenticated users. This allows an attacker to store malicious markup that is subsequently executed in the browser of any visitor or an administrator reviewing the unapproved submission.
Recommendations
Update the plugin to version 2.9.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubio Ai Page Builder