Cross-Site Scripting Vulnerability in AI Builder WordPress Plugin
CVE-2026-85678
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 11 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-85678?
The AI Builder WordPress plugin, prior to version 2.7.8, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw allows users with contributor level access and higher to submit unsanitized custom JavaScript code. When this code is executed within a script tag on the front end, it affects any user viewing the post, including editors or administrators. Consequently, this could lead to the execution of malicious scripts in the browsers of these users, potentially compromising site security.
Affected Version(s)
AI Builder 2.4.1 < 2.7.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.