VYPR
Medium severity6.5NVD Advisory· Published Mar 31, 2026· Updated Apr 24, 2026

CVE-2026-34887

CVE-2026-34887

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stored XSS.This issue affects Kubio AI Page Builder: from n/a through 2.7.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Kubio AI Page Builder through 2.7.0 allows privileged users to inject malicious scripts into web pages.

What is the vulnerability?

CVE-2026-34887 is a stored Cross-Site Scripting (XSS) vulnerability in the Extend Themes Kubio AI Page Builder plugin for WordPress, affecting versions from n/a through 2.7.0. The issue stems from improper neutralization of input during web page generation, allowing an attacker to inject arbitrary scripts that persist on the server and execute in the context of visitors' browsers [1].

How is it exploited?

Exploitation requires a privileged user (e.g., an editor or administrator) to interact with a crafted payload – such as clicking a malicious link, visiting a prepared page, or submitting a form. The attack is launched by a lower-privileged role that can store the malicious input, which then executes when other privileged users or site visitors load the affected page [1].

Impact

Successful exploitation enables a malicious actor to inject scripts that can redirect visitors, display unwanted advertisements, or deliver arbitrary HTML payloads. This can compromise the integrity and user trust of the website, as injected content runs automatically when guests browse the site [1].

Mitigation

The vendor has released version 2.7.1 which resolves the vulnerability. Patchstack users can enable auto-updates for vulnerable plugins. Immediate update to version 2.7.1 or later is strongly recommended; if updating is not possible, contact your hosting provider for assistance [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

2