---
id: CVE-2026-88782
title: >-
  The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the
  URI scheme of a user-supplied value before outputting it as a link target,
  allowing users with the contributor role and above to store a payload which
  executes…
summary: >-
  The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the
  URI scheme of a user-supplied value before outputting it as a link target,
  allowing users with the contributor role and above to store a payload which
  executes…
severity: none
cwe:
  - CWE-79
product: Kubio AI Page Builder
affected:
  - kubio_ai_page_builder < 2.9.3
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:44.740'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88782'
references:
  - url: 'https://wpscan.com/vulnerability/b45063f1-65a0-44cb-9565-0242f30fd7a3/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.565Z'
---

## Overview

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator previewing the unpublished submission.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
