{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/kubio/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kubio:kubio_ai_page_builder:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-100107"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kubio AI Page Builder (\u003c= 2.9.2)"],"_cs_severities":["high"],"_cs_tags":["xss","wordpress","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Kubio"],"content_html":"\u003cp\u003eThe Kubio AI Page Builder plugin for WordPress, in all versions up to and including 2.9.2, contains a vulnerability resulting from insufficient input sanitization and output escaping within the 'comment' parameter. This flaw allows unauthenticated attackers to perform stored Cross-Site Scripting (XSS) attacks. By injecting malicious JavaScript into the comment field, an attacker can ensure the script executes whenever an authorized user or administrator views the compromised page. This vulnerability poses a significant risk to WordPress sites relying on this plugin, as it could facilitate session hijacking, unauthorized administrative actions, or the redirection of users to malicious infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of any user who views an injected page. This can lead to full compromise of the user's session within the WordPress environment, potential exfiltration of sensitive administrative data, or the delivery of malicious content to end-users visiting the site.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Kubio AI Page Builder plugin to the latest version, ensuring it exceeds 2.9.2, to remediate CVE-2026-100107.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) to filter common XSS payloads, specifically targeting POST requests to the WordPress comment submission endpoint.\u003c/li\u003e\n\u003cli\u003eAudit existing comment sections for unexpected script tags or encoded payloads using established security scanners.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T08:23:11Z","date_published":"2026-10-02T08:23:11Z","id":"https://feed.craftedsignal.io/briefs/2026-10-02-kubio-xss/","summary":"The Kubio AI Page Builder plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability in the 'comment' parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of victim browsers.","title":"Stored XSS Vulnerability in Kubio AI Page Builder","url":"https://feed.craftedsignal.io/briefs/2026-10-02-kubio-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Kubio","version":"https://jsonfeed.org/version/1.1"}