<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Kubio - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/kubio/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 08:23:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/kubio/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS Vulnerability in Kubio AI Page Builder</title><link>https://feed.craftedsignal.io/briefs/2026-10-02-kubio-xss/</link><pubDate>Fri, 02 Oct 2026 08:23:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-02-kubio-xss/</guid><description>The Kubio AI Page Builder plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability in the 'comment' parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of victim browsers.</description><content:encoded><![CDATA[<p>The Kubio AI Page Builder plugin for WordPress, in all versions up to and including 2.9.2, contains a vulnerability resulting from insufficient input sanitization and output escaping within the 'comment' parameter. This flaw allows unauthenticated attackers to perform stored Cross-Site Scripting (XSS) attacks. By injecting malicious JavaScript into the comment field, an attacker can ensure the script executes whenever an authorized user or administrator views the compromised page. This vulnerability poses a significant risk to WordPress sites relying on this plugin, as it could facilitate session hijacking, unauthorized administrative actions, or the redirection of users to malicious infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of any user who views an injected page. This can lead to full compromise of the user's session within the WordPress environment, potential exfiltration of sensitive administrative data, or the delivery of malicious content to end-users visiting the site.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering teams:</p>
<ul>
<li>Upgrade the Kubio AI Page Builder plugin to the latest version, ensuring it exceeds 2.9.2, to remediate CVE-2026-100107.</li>
<li>Implement a Web Application Firewall (WAF) to filter common XSS payloads, specifically targeting POST requests to the WordPress comment submission endpoint.</li>
<li>Audit existing comment sections for unexpected script tags or encoded payloads using established security scanners.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>wordpress</category><category>web-vulnerability</category></item></channel></rss>