WordPress Plugin Vulnerabilities

Kubio AI Page Builder < 2.9.3 - Contributor+ Stored XSS via Image Gallery Item URL Attribute

Description

The plugin does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.

Proof of Concept

Affects Plugins

Fixed in 2.9.3

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-10-01 (about 2 days ago)
Added
2026-10-01 (about 1 day ago)
Last Updated
2026-10-01 (about 1 day ago)

Other