漏洞  ·  2026-10-04

Kubio AI Page Builder stored XSS cluster: unauthenticated SVG/HTML allowlist widening and comment param injection (CVE-2026-100107, CVE-2026-88783, CVE-2026-88782)

漏洞Medium 影响GlobalCVE-2026-100107
NVD published (2026-10-02/03) three related stored-XSS flaws in the Kubio AI Page Builder WordPress plugin (an AI-driven page builder), all fixed in 2.9.3: an unauthenticated stored XSS in the comment parameter, an HTML-allowlist widening that extended the editor's permitted element set to unauthenticated comment filtering, and a URI-scheme validation gap enabling contributor-level stored payloads.
AI page-builder plugins are increasingly deployed and manage substantial web content; stored XSS executing in an admin's browser is a direct path to admin-session compromise (and thus the site's AI content/config). The unauthenticated trigger on 100107/88783 broadens who can plant the payload.
CVE-2026-100107 (CVSS 7.2): stored XSS via the 'comment' parameter due to insufficient sanitization, exploitable by unauthenticated users. CVE-2026-88783 (CVSS 8.8): the plugin widened the allowed HTML elements set (SVG allowances) beyond the editor context, applying that wider allowlist to filtering of unauthenticated user content, enabling stored script execution. CVE-2026-88782 (CVSS 6.8): unsanitized link-target URI scheme lets contributor+ users store a payload executing when an admin follows the link
Kubio AI Page Builder for WordPress ≤ 2.9.2 (fixed in 2.9.3)
Upgrade to Kubio AI Page Builder 2.9.3; scope the widened HTML/SVG allowlist strictly to the editor rendering context and do not apply it to public comment/user content
NVD: CVE-2026-100107 (Kubio)WPScan: CVE-2026-88783Wordfence threat-intel entry for Kubio 2.9.2
在实时动态中查看 浏览更多 AI 安全与治理相关发现 — 每日清晨更新。
打开动态 →