CVE-2026-88782 PUBLISHED

Kubio AI Page Builder < 2.9.3 - Contributor+ Stored XSS via Image Gallery Item URL Attribute

Assigner: WPScan
Reserved: 10.09.2026 Published: 03.10.2026 Updated: 03.10.2026

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.

Product Status

Vendor Unknown
Product Kubio AI Page Builder
Versions Default: unaffected
  • affected from 0 to 2.9.3 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE