{"id":"CVE-2026-88782","title":"The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes…","summary":"The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes…","severity":"none","cwe":["CWE-79"],"product":"Kubio AI Page Builder","affected":["kubio_ai_page_builder < 2.9.3"],"published":"2026-10-03","updated":"2026-10-03","sourceUpdated":"2026-10-03T06:16:44.740","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88782","references":[{"url":"https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-03T06:39:57.565Z","slug":"CVE-2026-88782","body":"## Overview\n\nThe Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}