PT-2025-38508 · WordPress+1 · Kubio Ai Page Builder+1

Wesley

·

Published

2025-09-19

·

Updated

2025-09-19

·

CVE-2025-8487

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Kubio AI Page Builder plugin for WordPress versions up to and including 2.6.3
Description The Kubio AI Page Builder plugin for WordPress is susceptible to unauthorized plugin installation due to a missing capability check on the kubio-image-hub-install-plugin AJAX action. This allows authenticated attackers with Subscriber-level access or higher to install the Image Hub plugin.
Recommendations Update Kubio AI Page Builder plugin to a version later than 2.6.3.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-8487

Affected Products

Image Hub
Kubio Ai Page Builder