Sceawere

Vulnerability Detail

CVE-2026-88782UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kubio AI Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
13h ago
Vendor
Unknown
Product
Kubio AI Page Builder
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-10-03T06:16:44.740Z",
  "pubdate": "2026-10-03T06:16:44.740Z",
  "executiveSummary": "The Kubio AI Page Builder WordPress plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper input sanitization and URI scheme validation. This flaw allows authenticated users with the 'contributor' role or higher to inject and store malicious payloads within link target attributes. When a victim, such as an administrator, views or interacts with the compromised link, the malicious script executes within their browser session. The primary risk involves the unauthorized execution of JavaScript in the context of the victim's session, potentially leading to privilege escalation, session hijacking, or unauthorized administrative actions. This vulnerability exists because the plugin fails to enforce strict allow-listing for URI protocols, permitting dangerous schemes such as 'javascript:'. Exploitation requires authenticated access to the WordPress dashboard with at least contributor privileges. Given the capacity for attackers to target administrative users through previewing mechanisms, this vulnerability poses a significant risk to the integrity and confidentiality of the WordPress environment.",
  "technicalDetails": "The root cause of this vulnerability is an insufficient security control mechanism regarding the handling of user-supplied URI values within the Kubio AI Page Builder plugin. Specifically, the component responsible for processing link target configurations fails to validate the URI scheme before rendering the input into the HTML output. By omitting a strict allow-list check for URI protocols, the application inadvertently permits the use of the 'javascript:' pseudo-protocol within href attributes.\nThe exploitation flow begins when an authenticated user, holding the contributor role or higher, navigates to the Kubio AI editor interface. Within a link configuration field, the attacker inputs a payload formatted as 'javascript:[malicious_code]'. Because the plugin performs no server-side validation or output encoding on this specific attribute, the payload is persisted directly into the WordPress database as part of the page or post content.\nThe attack vector is triggered when a legitimate user, such as an administrator, views the content or utilizes the WordPress preview functionality on the affected submission. When the browser parses the rendered HTML, it interprets the 'javascript:' scheme as an executable instruction rather than a navigational link. Consequently, the stored script executes in the context of the victim’s authenticated session. This allows the attacker to perform actions with the victim's permissions, such as modifying site settings, creating new administrative accounts, or exfiltrating sensitive data stored within the browser, including session cookies.\nThe vulnerability affects all versions of Kubio AI Page Builder prior to 2.9.3. The impact is significant because it bypasses standard WordPress role-based access controls by leveraging an elevated user's session to perform unauthorized actions. Since the payload is stored, the attack does not require immediate interaction from the victim beyond simply accessing the malicious content, making it a classic Stored XSS attack. The lack of proper input validation in the plugin's data processing logic constitutes a critical failure in secure development practices, specifically concerning the handling of untrusted user input before outputting it to the DOM."
}
CVE-2026-88782: Kubio AI Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.8) | Sceawere