WordPress Plugin Vulnerabilities

Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content

Description

The plugin does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the plugin's own script later executes in the browser of any visitor, or of an administrator reviewing the still-unapproved submission.

Proof of Concept

Affects Plugins

Fixed in 2.9.3

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-01 (about 2 days ago)
Added
2026-10-01 (about 1 day ago)
Last Updated
2026-10-02 (about 8 hours ago)

Other