事件经过
NVD published (2026-10-02/03) three related stored-XSS flaws in the Kubio AI Page Builder WordPress plugin (an AI-driven page builder), all fixed in 2.9.3: an unauthenticated stored XSS in the comment parameter, an HTML-allowlist widening that extended the editor's permitted element set to unauthenticated comment filtering, and a URI-scheme validation gap enabling contributor-level stored payloads.
影响分析
AI page-builder plugins are increasingly deployed and manage substantial web content; stored XSS executing in an admin's browser is a direct path to admin-session compromise (and thus the site's AI content/config). The unauthenticated trigger on 100107/88783 broadens who can plant the payload.
攻击途径
CVE-2026-100107 (CVSS 7.2): stored XSS via the 'comment' parameter due to insufficient sanitization, exploitable by unauthenticated users. CVE-2026-88783 (CVSS 8.8): the plugin widened the allowed HTML elements set (SVG allowances) beyond the editor context, applying that wider allowlist to filtering of unauthenticated user content, enabling stored script execution. CVE-2026-88782 (CVSS 6.8): unsanitized link-target URI scheme lets contributor+ users store a payload executing when an admin follows the link
受影响系统
Kubio AI Page Builder for WordPress ≤ 2.9.2 (fixed in 2.9.3)
缓解措施
Upgrade to Kubio AI Page Builder 2.9.3; scope the widened HTML/SVG allowlist strictly to the editor rendering context and do not apply it to public comment/user content