Stored Cross-Site Scripting Vulnerability in Kubio AI Page Builder for WordPress
CVE-2026-100107
7.2HIGH
What is CVE-2026-100107?
The Kubio AI Page Builder plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitization and output escaping. This flaw allows unauthenticated attackers to inject arbitrary web scripts through the 'comment' parameter, which can execute whenever users access an affected page. All versions up to and including 2.9.2 are impacted, making it crucial for site administrators to implement security measures promptly.
Affected Version(s)
Kubio AI Page Builder 0 <= 2.9.2