CVE-2026-34887: WordPress Kubio AI Page Builder plugin <= 2.7.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stored XSS.This issue affects Kubio AI Page Builder: from n/a through 2.7.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34887?
CVE-2026-34887 has a severity level that indicates a significant risk due to its Cross-Site Scripting (XSS) nature.
How do I fix CVE-2026-34887?
To fix CVE-2026-34887, update the Extend Themes Kubio AI Page Builder plugin to a version higher than 2.7.0.
What systems are affected by CVE-2026-34887?
CVE-2026-34887 affects the Extend Themes Kubio AI Page Builder plugin versions up to and including 2.7.0.
What impact does CVE-2026-34887 have on my website?
CVE-2026-34887 can allow attackers to execute malicious scripts on your website, compromising user data and site integrity.
Is CVE-2026-34887 a previously known vulnerability?
CVE-2026-34887 appears to be a newly discovered vulnerability specific to the Kubio AI Page Builder plugin.