high · CVSS v3 6.8 · EPSS 0.00152
CVE-2026-88782
The Kubio AI Page Builder WordPress plugin (v<2.9.3) fails to validate URI schemes in user-supplied link targets, enabling stored XSS. Contr
Overview
The Kubio AI Page Builder WordPress plugin (v<2.9.3) fails to validate URI schemes in user-supplied link targets, enabling stored XSS. Contributors and higher can inject malicious payloads that execute in the browsers of anyone who clicks the link, including administrators previewing drafts. This flaw can lead to session hijacking or defacement.
Description
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.
Impact
Confidentiality: attackers can exfiltrate session cookies or other sensitive data. Integrity: malicious scripts can alter page content or deface sites. Availability: not directly impacted. Defenders: site admins, contributors, and users who click links. Attackers can hijack admin sessions or inject malicious content.
Remediation
Upgrade Kubio AI Page Builder to version 2.9.3 or later. If upgrade not possible, disable link target functionality for contributor role or lower. Apply a Content Security Policy that blocks unsafe-inline and restricts script sources. Monitor for unexpected link targets in content and review user permissions.
Risk context
Severity is high (CVSS 6.8) but EPSS is low (0.00152), indicating a low probability of exploitation in the wild. Nonetheless, the vulnerability can be abused by insiders with contributor access, so prompt patching is recommended.
Affected products
- Kubio AI Page Builder
- WordPress plugin Kubio AI Page Builder
- Kubio AI Page Builder 2.9.2
Scores
- Severity
- high
- CVSS v2
- 8.3
- CVSS v3
- 6.8
- CVSS v4
- —
- EPSS
- 0.00152