rootpwn

critical · CVSS v3 8.8 · EPSS 0.00172

CVE-2026-88783

The Kubio AI Page Builder WordPress plugin before 2.9.3 fails to restrict expanded HTML element set to editor context, allowing unauthentica

Overview

The Kubio AI Page Builder WordPress plugin before 2.9.3 fails to restrict expanded HTML element set to editor context, allowing unauthenticated users to inject markup that is later executed in browsers of visitors or admins. This flaw can lead to cross‑site scripting (XSS) attacks. It affects sites using older Kubio plugin versions.

Description

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before 2.9.3's own script later executes in the browser of any visitor, or of an administrator reviewing the still-unapproved submission.

Impact

Confidentiality: malicious scripts could exfiltrate data via XSS. Integrity: attackers could modify page content or inject malicious code. Availability: minimal direct impact but could degrade user experience. Impacted parties: site visitors, administrators, and site owners.

Remediation

Update Kubio AI Page Builder to version 2.9.3 or later. If update is not possible, disable the plugin or restrict unauthenticated content submission. Ensure WordPress core and other plugins are up to date. Apply web application firewall rules to block suspicious HTML tags.

Risk context

Critical severity indicates high potential impact; EPSS of 0.00172 suggests low likelihood but defenders should still prioritize patching promptly.

Affected products

  • Kubio AI Page Builder
  • WordPress

Scores

Severity
critical
CVSS v2
10
CVSS v3
8.8
CVSS v4
—
EPSS
0.00172

XSS WordPress Kubio Critical WebApplication ContentInjection Patch

← All CVEs