CVE-2026-94167: WordPress Kubio AI Page Builder plugin <= 2.9.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder kubio allows Reflected XSS.This issue affects Kubio AI Page Builder: from n/a through 2.9.3.
Affected Software
Event History
Frequently Asked Questions
Which plugin versions are affected?
Kubio AI Page Builder versions through 2.9.3 are affected. The available data does not identify a fixed version.
What must an attacker do to exploit this issue?
The issue is a reflected XSS vulnerability with network attack vector, low attack complexity, no required privileges, and required user interaction. Exploitation therefore requires persuading a user to interact with attacker-controlled input, such as by visiting a crafted request.
What is the impact if exploitation succeeds?
The CVSS vector indicates low impacts to confidentiality, integrity, and availability, with scope changed. An attacker may be able to execute script in a victim's browser within the affected web context.