The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.
cve CVE-2026-88782 2 sources, 2 claims · Watch
NVD writes:
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission. the claim
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission. the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | unknown/kubio_ai_page_builderNVD says “Unknown · Kubio AI Page Builder” |
| made_by | unknownNVD says “Unknown” |
What each source says
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Cvss cvss | GitHub advisories | 6.8receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-88782",
"cvss": {
"score": 6.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-79",
"name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
}
],
"description": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.",
"ghsa_id": "GHSA-gf46-mg37-6fp9",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-gf46-mg37-6fp9",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-gf46-mg37-6fp9"
},
{
"type": "CVE",
"value": "CVE-2026-88782"
}
],
"nvd_published_at": "2026-10-03T06:16:44Z",
"published_at": "2026-10-03T06:31:13Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-88782",
"https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3",
"https://github.com/advisories/GHSA-gf46-mg37-6fp9"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a...",
"type": "unreviewed",
"updated_at": "2026-10-03T18:32:05Z",
"url": "https://api.github.com/advisories/GHSA-gf46-mg37-6fp9",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| Cvss cvss | NVD | 6.8receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Kubio AI Page Builder",
"vendor": "Unknown",
"versions": [
{
"lessThan": "2.9.3",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission."
}
],
"id": "CVE-2026-88782",
"lastModified": "2026-10-03T16:16:40.277",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 0.9,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-88782",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:01:30.605310Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-03T06:16:44.740",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Cwe cwe | GitHub advisories | CWE-79receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-88782",
"cvss": {
"score": 6.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-79",
"name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
}
],
"description": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.",
"ghsa_id": "GHSA-gf46-mg37-6fp9",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-gf46-mg37-6fp9",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-gf46-mg37-6fp9"
},
{
"type": "CVE",
"value": "CVE-2026-88782"
}
],
"nvd_published_at": "2026-10-03T06:16:44Z",
"published_at": "2026-10-03T06:31:13Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-88782",
"https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3",
"https://github.com/advisories/GHSA-gf46-mg37-6fp9"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a...",
"type": "unreviewed",
"updated_at": "2026-10-03T18:32:05Z",
"url": "https://api.github.com/advisories/GHSA-gf46-mg37-6fp9",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| Product product | NVD | Kubio AI Page Builderreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Kubio AI Page Builder",
"vendor": "Unknown",
"versions": [
{
"lessThan": "2.9.3",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission."
}
],
"id": "CVE-2026-88782",
"lastModified": "2026-10-03T16:16:40.277",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 0.9,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-88782",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:01:30.605310Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-03T06:16:44.740",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | GitHub advisories | mediumreceipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-88782",
"cvss": {
"score": 6.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-79",
"name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
}
],
"description": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.",
"ghsa_id": "GHSA-gf46-mg37-6fp9",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-gf46-mg37-6fp9",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-gf46-mg37-6fp9"
},
{
"type": "CVE",
"value": "CVE-2026-88782"
}
],
"nvd_published_at": "2026-10-03T06:16:44Z",
"published_at": "2026-10-03T06:31:13Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-88782",
"https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3",
"https://github.com/advisories/GHSA-gf46-mg37-6fp9"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a...",
"type": "unreviewed",
"updated_at": "2026-10-03T18:32:05Z",
"url": "https://api.github.com/advisories/GHSA-gf46-mg37-6fp9",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| Status status | NVD | Receivedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Kubio AI Page Builder",
"vendor": "Unknown",
"versions": [
{
"lessThan": "2.9.3",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission."
}
],
"id": "CVE-2026-88782",
"lastModified": "2026-10-03T16:16:40.277",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 0.9,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-88782",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:01:30.605310Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-03T06:16:44.740",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | Unknownreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Kubio AI Page Builder",
"vendor": "Unknown",
"versions": [
{
"lessThan": "2.9.3",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission."
}
],
"id": "CVE-2026-88782",
"lastModified": "2026-10-03T16:16:40.277",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 0.9,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-88782",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:01:30.605310Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-03T06:16:44.740",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission. zetlyn/cve-nvd · 2026-10-03 | cvss 6.8 product Kubio AI Page Builder status Received vendor Unknown | source |
| The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a... zetlyn/cve-ghsa · 2026-10-03 | cvss 6.8 cwe CWE-79 severity medium | source |