Sceawere
Vulnerability Detail
CVE-2026-94167UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in Kubio AI
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Extend Themes
- Product
- Kubio AI Page Builder
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder kubio allows Reflected XSS.This issue affects Kubio AI Page Builder: from n/a through 2.9.3.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:40.193Z",
"pubdate": "2026-10-09T10:16:40.193Z",
"executiveSummary": "The Kubio AI Page Builder plugin for WordPress is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. This flaw arises from the improper neutralization of user-supplied input during the generation of web pages.\nThe vulnerability allows an unauthenticated or authenticated attacker to inject malicious client-side scripts—typically JavaScript—into the target web application. When a victim interacts with a specially crafted URL containing the malicious payload, the script executes within the context of the victim's browser session.\nThis can lead to significant security compromises, including the theft of session cookies, unauthorized actions performed on behalf of the user, redirection to malicious domains, and the defacement of the rendered web page. The risk is elevated because the attack does not require direct access to the server, only the ability to convince a user to click a crafted link. All versions of Kubio AI Page Builder from n/a through 2.9.3 are affected. Organizations should prioritize updating to a secure version once available and implementing robust input validation controls.",
"technicalDetails": "The root cause of the vulnerability is the application's failure to properly sanitize or escape user-controlled input before reflecting it back into the HTTP response. In the context of the Kubio AI Page Builder plugin, the application likely accepts parameters via GET or POST requests and embeds these values directly into the HTML output without adequate output encoding.\nThe attack flow commences when an attacker identifies a reflection point within the application—specifically an input parameter that is rendered back to the user without server-side validation or output filtering. The attacker constructs a malicious URL incorporating a JavaScript payload, such as '<script>alert(document.cookie)</script>', within the vulnerable parameter. This URL is then distributed to potential targets via phishing, social engineering, or public forums.\nUpon a victim visiting the crafted URL, the server processes the request and incorporates the malicious payload directly into the Document Object Model (DOM) of the returned web page. The browser, perceiving the payload as legitimate code originating from the trusted origin of the website, executes the script. Because the script runs in the context of the victim's session, it gains access to sensitive data stored in the browser, such as Session IDs, CSRF tokens, and localStorage variables.\nThis reflected XSS exploit does not necessitate prior authentication, as the execution occurs entirely within the client's browser session upon accessing the malformed URI. The impact is primarily client-side; however, in a WordPress environment, this can be leveraged to escalate privileges if an administrator is targeted. For example, the script could perform administrative actions, such as creating new user accounts, modifying plugin configurations, or injecting backdoors into the theme files. Given that the Kubio AI Page Builder handles complex page rendering logic, the surface area for such reflections is typically high, and the lack of proper context-aware output encoding across the plugin's various output functions likely facilitates this vulnerability."
}