Kubio AI Page Builder Security & Risk Analysis

wordpress.org/plugins/kubio

Using the power of AI, Kubio gives you a head start by generating a first draft of your website, which you can further customize to your liking.

100K active installs v2.7.3 PHP 7.4+ WP 5.8+ Updated Apr 15, 2026
blocksgutenberglanding-pagepage-builderwebsite-builder
89
A · Safe
CVEs total6
Unpatched0
Last CVEApr 16, 2026
Safety Verdict

Is Kubio AI Page Builder Safe to Use in 2026?

Generally Safe

Score 89/100

Kubio AI Page Builder has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

6 known CVEsLast CVE: Apr 16, 2026Updated 1mo ago
Risk Assessment

The static analysis of Kubio v2.7.1 indicates a generally strong adherence to secure coding practices. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a positive sign, as is the complete use of prepared statements for SQL queries and proper output escaping. The plugin's file operations and external HTTP requests are also noted, but without further context on their implementation, their security impact is unclear.

However, the plugin's vulnerability history presents a significant concern. With four known CVEs, including one critical and three medium severity, and common vulnerability types such as Missing Authorization, Path Traversal, and Cross-site Scripting, there's a clear pattern of past security weaknesses. The fact that there are currently no unpatched vulnerabilities is a positive mitigating factor, but the historical prevalence of critical and medium severity issues suggests a recurring need for careful auditing and prompt patching.

The inclusion of Lodash as a bundled library, while common, could potentially introduce risks if not kept up-to-date and if the specific version is vulnerable. Overall, while the current version exhibits good static code hygiene, the historical vulnerability record warrants caution and ongoing vigilance.

Key Concerns

  • High number of historical critical/medium vulnerabilities
  • Presence of critical historical vulnerability
  • Bundled library (Lodash)
Vulnerabilities
6 published

Kubio AI Page Builder Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
3 CVEs in 2025
2025
2 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
5

6 total CVEs

CVE-2026-5427medium · 5.3Missing Authorization

Kubio AI Page Builder <= 2.7.2 - Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes

Apr 16, 2026 Patched in 2.7.3 (1d)
CVE-2026-34887medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Kubio AI Page Builder <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 31, 2026 Patched in 2.7.1 (3d)
CVE-2025-8487medium · 5.4Missing Authorization

Kubio AI Page Builder <= 2.6.3 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation

Sep 18, 2025 Patched in 2.6.5 (1d)
CVE-2025-2294critical · 9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion

Mar 27, 2025 Patched in 2.5.2 (1d)
CVE-2024-13516medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Kubio AI Page Builder <= 2.3.5 - Reflected Cross-Site Scripting

Jan 17, 2025 Patched in 2.4.0 (1d)
CVE-2024-39661medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Kubio AI Page Builder <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 1, 2024 Patched in 2.2.5 (7d)
Version History

Kubio AI Page Builder Release Timeline

v2.7.3Current
v2.7.21 CVE73 files changed
v2.7.11 CVE28 files changed
v2.6.72 CVEs57 files changed
v2.6.62 CVEs43 files changed
v2.6.52 CVEs53 files changed
v2.6.23 CVEs286 files changed
v2.5.33 CVEs29 files changed
v2.5.23 CVEs28 files changed
v2.5.14 CVEs107 files changed
v2.4.54 CVEs48 files changed
v2.4.24 CVEs3 files changed
v2.4.14 CVEs44 files changed
Code Analysis
Analyzed Mar 16, 2026

Kubio AI Page Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
1

Bundled Libraries

Lodash
Attack Surface

Kubio AI Page Builder Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Kubio AI Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 15, 2026
PHP min version7.4
Downloads1.7M

Community Trust

Rating86/100
Number of ratings67
Active installs100K
Developer Profile

Kubio AI Page Builder Developer Profile

Extend Themes

60 plugins · 430K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
127 days
View full developer profile
Detection Fingerprints

How We Detect Kubio AI Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kubio/build/editor.css/wp-content/plugins/kubio/build/editor.js/wp-content/plugins/kubio/build/styles.css/wp-content/plugins/kubio/build/styles.js/wp-content/plugins/kubio/build/frontend.css/wp-content/plugins/kubio/build/frontend.js
Script Paths
/wp-content/plugins/kubio/build/editor.js/wp-content/plugins/kubio/build/styles.js/wp-content/plugins/kubio/build/frontend.js
Version Parameters
kubio/build/editor.css?ver=kubio/build/editor.js?ver=kubio/build/styles.css?ver=kubio/build/styles.js?ver=kubio/build/frontend.css?ver=kubio/build/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
kubio-editor-contentkubio-elementkubio-blockkubio-editablekubio-page
HTML Comments
<!-- wp:kubio/paragraph --><!-- wp:kubio/heading --><!-- wp:kubio/image --><!-- wp:kubio/button -->+6 more
Data Attributes
data-kubio-iddata-kubio-element-typedata-kubio-block-typedata-kubio-editable-content
JS Globals
kubioEditorkubioGlobalSettingsKubioPageBuilderKubioConfig
REST Endpoints
/wp-json/kubio/v1/settings/wp-json/kubio/v1/templates/wp-json/kubio/v1/assets
FAQ

Frequently Asked Questions about Kubio AI Page Builder