rootpwn

high · CVSS v3 6.8 · EPSS 0.00152

CVE-2026-88782

The Kubio AI Page Builder WordPress plugin (v<2.9.3) fails to validate URI schemes in user-supplied link targets, enabling stored XSS. Contr

Overview

The Kubio AI Page Builder WordPress plugin (v<2.9.3) fails to validate URI schemes in user-supplied link targets, enabling stored XSS. Contributors and higher can inject malicious payloads that execute in the browsers of anyone who clicks the link, including administrators previewing drafts. This flaw can lead to session hijacking or defacement.

Description

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.

Impact

Confidentiality: attackers can exfiltrate session cookies or other sensitive data. Integrity: malicious scripts can alter page content or deface sites. Availability: not directly impacted. Defenders: site admins, contributors, and users who click links. Attackers can hijack admin sessions or inject malicious content.

Remediation

Upgrade Kubio AI Page Builder to version 2.9.3 or later. If upgrade not possible, disable link target functionality for contributor role or lower. Apply a Content Security Policy that blocks unsafe-inline and restricts script sources. Monitor for unexpected link targets in content and review user permissions.

Risk context

Severity is high (CVSS 6.8) but EPSS is low (0.00152), indicating a low probability of exploitation in the wild. Nonetheless, the vulnerability can be abused by insiders with contributor access, so prompt patching is recommended.

Affected products

  • Kubio AI Page Builder
  • WordPress plugin Kubio AI Page Builder
  • Kubio AI Page Builder 2.9.2

Scores

Severity
high
CVSS v2
8.3
CVSS v3
6.8
CVSS v4
—
EPSS
0.00152

XSS Stored XSS WordPress Kubio Contributor Link Injection CSP Patch

← All CVEs