critical · CVSS v3 8.8 · EPSS 0.00172
CVE-2026-88783
The Kubio AI Page Builder WordPress plugin before 2.9.3 fails to restrict expanded HTML element set to editor context, allowing unauthentica
Overview
The Kubio AI Page Builder WordPress plugin before 2.9.3 fails to restrict expanded HTML element set to editor context, allowing unauthenticated users to inject markup that is later executed in browsers of visitors or admins. This flaw can lead to cross‑site scripting (XSS) attacks. It affects sites using older Kubio plugin versions.
Description
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before 2.9.3's own script later executes in the browser of any visitor, or of an administrator reviewing the still-unapproved submission.
Impact
Confidentiality: malicious scripts could exfiltrate data via XSS. Integrity: attackers could modify page content or inject malicious code. Availability: minimal direct impact but could degrade user experience. Impacted parties: site visitors, administrators, and site owners.
Remediation
Update Kubio AI Page Builder to version 2.9.3 or later. If update is not possible, disable the plugin or restrict unauthenticated content submission. Ensure WordPress core and other plugins are up to date. Apply web application firewall rules to block suspicious HTML tags.
Risk context
Critical severity indicates high potential impact; EPSS of 0.00172 suggests low likelihood but defenders should still prioritize patching promptly.
Affected products
- Kubio AI Page Builder
- WordPress
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- 0.00172