WordPress Plugin Vulnerabilities

AI Builder 2.4.1 - 2.7.7 - Contributor+ Stored XSS via Post JavaScript

Description

The plugin does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of anyone who views the post, including the editor or administrator who reviews it.

Proof of Concept

Affects Plugins

Fixed in 2.7.8

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
md. minaruzzaman shovon
Submitter
md. minaruzzaman shovon
Verified
Yes

Timeline

Publicly Published
2026-09-09 (about 2 days ago)
Added
2026-09-09 (about 1 day ago)
Last Updated
2026-09-09 (about 1 day ago)

Other