CVE-2026-34887
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stored XSS.This issue affects Kubio AI Page Builder: from n/a through 2.7.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Kubio AI Page Builder through 2.7.0 allows privileged users to inject malicious scripts into web pages.
What is the vulnerability?
CVE-2026-34887 is a stored Cross-Site Scripting (XSS) vulnerability in the Extend Themes Kubio AI Page Builder plugin for WordPress, affecting versions from n/a through 2.7.0. The issue stems from improper neutralization of input during web page generation, allowing an attacker to inject arbitrary scripts that persist on the server and execute in the context of visitors' browsers [1].
How is it exploited?
Exploitation requires a privileged user (e.g., an editor or administrator) to interact with a crafted payload – such as clicking a malicious link, visiting a prepared page, or submitting a form. The attack is launched by a lower-privileged role that can store the malicious input, which then executes when other privileged users or site visitors load the affected page [1].
Impact
Successful exploitation enables a malicious actor to inject scripts that can redirect visitors, display unwanted advertisements, or deliver arbitrary HTML payloads. This can compromise the integrity and user trust of the website, as injected content runs automatically when guests browse the site [1].
Mitigation
The vendor has released version 2.7.1 which resolves the vulnerability. Patchstack users can enable auto-updates for vulnerable plugins. Immediate update to version 2.7.1 or later is strongly recommended; if updating is not possible, contact your hosting provider for assistance [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2.7.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026)Wordfence Blog · Apr 23, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (March 30, 2026 to April 5, 2026)Wordfence Blog · Apr 9, 2026