Skip to content
Threat Feed
high advisory

Stored XSS Vulnerability in Kubio AI Page Builder

The Kubio AI Page Builder plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability in the 'comment' parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of victim browsers.

CVE search metadata

CVE search record: CVE-2026-100107. Severity: high. CVSS: 7.2. KEV: no. Product: Kubio AI Page Builder (<= 2.9.2). Brief: Stored XSS Vulnerability in Kubio AI Page Builder. Brief link: https://feed.craftedsignal.io/briefs/2026-10-02-kubio-xss/

The Kubio AI Page Builder plugin for WordPress, in all versions up to and including 2.9.2, contains a vulnerability resulting from insufficient input sanitization and output escaping within the 'comment' parameter. This flaw allows unauthenticated attackers to perform stored Cross-Site Scripting (XSS) attacks. By injecting malicious JavaScript into the comment field, an attacker can ensure the script executes whenever an authorized user or administrator views the compromised page. This vulnerability poses a significant risk to WordPress sites relying on this plugin, as it could facilitate session hijacking, unauthorized administrative actions, or the redirection of users to malicious infrastructure.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of any user who views an injected page. This can lead to full compromise of the user's session within the WordPress environment, potential exfiltration of sensitive administrative data, or the delivery of malicious content to end-users visiting the site.

Recommendation

Prioritized, concrete actions for detection engineering teams:

  • Upgrade the Kubio AI Page Builder plugin to the latest version, ensuring it exceeds 2.9.2, to remediate CVE-2026-100107.
  • Implement a Web Application Firewall (WAF) to filter common XSS payloads, specifically targeting POST requests to the WordPress comment submission endpoint.
  • Audit existing comment sections for unexpected script tags or encoded payloads using established security scanners.

Immediate actions

Upgrade Kubio AI Page Builder to version > 2.9.2

IT Operations 24h

Mitigations

Enable WAF rules to detect and block XSS payloads in comment parameters

immediate SOC

CVE-2026-100107