Cross-Site Scripting Vulnerability in Extend Themes Kubio AI Page Builder
CVE-2026-34887
6.5MEDIUM
What is CVE-2026-34887?
A vulnerability exists in the Extend Themes Kubio AI Page Builder, where improper neutralization of user input during web page generation can lead to stored cross-site scripting (XSS) attacks. This susceptibility allows an attacker to store malicious scripts in the application, potentially executing them in the context of users who access the affected pages. The issue impacts versions from n/a through 2.7.0, compromising website security and user data.
Affected Version(s)
Kubio AI Page Builder <= 2.7.0