CVE-2026-88783
Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before 2.9.3's own script later executes in the browser of any visitor, or of an administrator reviewing the still-unapproved submission.
| Vendor | unknown |
| Product | kubio ai page builder |
| Published | Oct 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown kubio ai page builder
Be the first to know when new unknown vulnerabilities affecting unknown kubio ai page builder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Kubio AI Page Builder
0 < 2.9.3
References
Credits
Jakub Herman WPScan