Stored XSS Vulnerability in Kubio AI Page Builder
The Kubio AI Page Builder plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability in the 'comment' parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of victim browsers.
CVE search metadata
CVE search record: CVE-2026-100107. Severity: high. CVSS: 7.2. KEV: no. Product: Kubio AI Page Builder (<= 2.9.2). Brief: Stored XSS Vulnerability in Kubio AI Page Builder. Brief link: https://feed.craftedsignal.io/briefs/2026-10-02-kubio-xss/
The Kubio AI Page Builder plugin for WordPress, in all versions up to and including 2.9.2, contains a vulnerability resulting from insufficient input sanitization and output escaping within the 'comment' parameter. This flaw allows unauthenticated attackers to perform stored Cross-Site Scripting (XSS) attacks. By injecting malicious JavaScript into the comment field, an attacker can ensure the script executes whenever an authorized user or administrator views the compromised page. This vulnerability poses a significant risk to WordPress sites relying on this plugin, as it could facilitate session hijacking, unauthorized administrative actions, or the redirection of users to malicious infrastructure.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of any user who views an injected page. This can lead to full compromise of the user's session within the WordPress environment, potential exfiltration of sensitive administrative data, or the delivery of malicious content to end-users visiting the site.
Recommendation
Prioritized, concrete actions for detection engineering teams:
- Upgrade the Kubio AI Page Builder plugin to the latest version, ensuring it exceeds 2.9.2, to remediate CVE-2026-100107.
- Implement a Web Application Firewall (WAF) to filter common XSS payloads, specifically targeting POST requests to the WordPress comment submission endpoint.
- Audit existing comment sections for unexpected script tags or encoded payloads using established security scanners.
Immediate actions
Upgrade Kubio AI Page Builder to version > 2.9.2
Mitigations
Enable WAF rules to detect and block XSS payloads in comment parameters
CVE-2026-100107