What is CVE-2026-16779?
A vulnerability in the Kubio AI Page Builder plugin for WordPress (up to version 2.8.5) allows authorization bypass due to improper verification of user permissions. This enables authenticated attackers with contributor-level access to perform unauthorized actions. Users should immediately update the plugin to the latest version.
Azərbaycanca: WordPress üçün Kubio AI Page Builder plaginində (2.8.5 və əvvəlki versiyalarda) avtorizasiya bypass zəifliyi aşkar edilib. Bu, 'contributor' səviyyəsindəki autentifikasiya olunmuş hücumçulara səlahiyyətsiz əməliyyatlar icra etməyə imkan verir. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of Kubio AI Page Builder are affected by CVE-2026-16779?
This authorization bypass vulnerability affects Kubio AI Page Builder plugin versions up to and including 2.8.5.
What minimum permission level is required for an attacker to exploit CVE-2026-16779?
An attacker must have authenticated contributor-level access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.