CVE-2026-85678 PUBLISHED

AI Builder 2.4.1 - 2.7.7 - Contributor+ Stored XSS via Post JavaScript

Assigner: WPScan
Reserved: 04.09.2026 Published: 11.09.2026 Updated: 11.09.2026

The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of anyone who views the post, including the editor or administrator who reviews it.

Product Status

Vendor Unknown
Product AI Builder
Versions Default: unaffected
  • affected from 2.4.1 to 2.7.8 (excl.)

Credits

  • md. minaruzzaman shovon finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE