The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a...

zetlyn/cve-ghsa vulnerability ghsa GHSA-gf46-mg37-6fp9 cve CVE-2026-88782 known 2026-10-03

https://github.com/advisories/GHSA-gf46-mg37-6fp9

Properties

cvss6.8
receipt
Source
GitHub advisories
Its words
6.8
Read by
field:cvss.score
Said since
2026-10-04 00:09 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
2026-10-04 00:09 UTC6.8
2026-10-03 12:05 UTC—
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-88782",
  "cvss": {
    "score": 6.8,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 6.8,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-79",
      "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
    }
  ],
  "description": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.",
  "ghsa_id": "GHSA-gf46-mg37-6fp9",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-gf46-mg37-6fp9",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-gf46-mg37-6fp9"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-88782"
    }
  ],
  "nvd_published_at": "2026-10-03T06:16:44Z",
  "published_at": "2026-10-03T06:31:13Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-88782",
    "https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3",
    "https://github.com/advisories/GHSA-gf46-mg37-6fp9"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T18:32:05Z",
  "url": "https://api.github.com/advisories/GHSA-gf46-mg37-6fp9",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-79
receipt
Source
GitHub advisories
Its words
CWE-79
Read by
field:cwes[].cwe_id
Said since
2026-10-04 00:09 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
2026-10-04 00:09 UTCCWE-79
2026-10-03 12:05 UTC—
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-88782",
  "cvss": {
    "score": 6.8,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 6.8,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-79",
      "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
    }
  ],
  "description": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.",
  "ghsa_id": "GHSA-gf46-mg37-6fp9",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-gf46-mg37-6fp9",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-gf46-mg37-6fp9"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-88782"
    }
  ],
  "nvd_published_at": "2026-10-03T06:16:44Z",
  "published_at": "2026-10-03T06:31:13Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-88782",
    "https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3",
    "https://github.com/advisories/GHSA-gf46-mg37-6fp9"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T18:32:05Z",
  "url": "https://api.github.com/advisories/GHSA-gf46-mg37-6fp9",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitymedium
receipt
Source
GitHub advisories
Its words
medium
Read by
field:severity
Said since
2026-10-04 00:09 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
2026-10-04 00:09 UTCmedium
2026-10-03 12:05 UTCunknown
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-88782",
  "cvss": {
    "score": 6.8,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 6.8,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-79",
      "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
    }
  ],
  "description": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.",
  "ghsa_id": "GHSA-gf46-mg37-6fp9",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-gf46-mg37-6fp9",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-gf46-mg37-6fp9"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-88782"
    }
  ],
  "nvd_published_at": "2026-10-03T06:16:44Z",
  "published_at": "2026-10-03T06:31:13Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-88782",
    "https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3",
    "https://github.com/advisories/GHSA-gf46-mg37-6fp9"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T18:32:05Z",
  "url": "https://api.github.com/advisories/GHSA-gf46-mg37-6fp9",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a... The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.