Junglewise Threat Intelligence

CVE-2026-85678: AI Builder WordPress plugin stored XSS in custom JavaScript

CVE-2026-85678 · Severity: medium · CVSS 6.8 · Published 2026-09-11

Executive brief

The AI Builder WordPress plugin before version 2.7.8 fails to sanitize custom JavaScript code that users with contributor-level access can attach to posts. An attacker with contributor permissions can inject malicious JavaScript that executes in the browsers of anyone viewing the post, including editors and administrators, potentially leading to account compromise or data theft.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the AI Builder WordPress plugin. The vulnerable component accepts custom JavaScript via the aibui_save_post_js AJAX action without sanitization or escaping before storing it in the database and echoing it inside a script tag on the front end. An authenticated attacker with contributor-level or higher permissions can exploit this by sending a POST request to wp-admin/admin-ajax.php with arbitrary JavaScript in the js_content parameter. The malicious script then executes in the browser of any user viewing the post, including administrators reviewing drafts. The vulnerability affects versions 2.4.1 through 2.7.7 and is fixed in version 2.7.8.

Affected products

  • AI Builder AI Builder 2.4.1 through 2.7.7

Timeline

  • 2026-09-09: disclosed
  • 2026-09-11: patched: Fixed in version 2.7.8

References