← WordPress Vulnerabilities
WordPress security by component

AI Builder

AI Builder (ai-builder) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 6.8.

Plugin slug: ai-builder

CVE-2026-85678: AI Builder permits contributor stored JavaScript

AI Builder before 2.7.8 lets Contributors save custom JavaScript against a post and echoes that value inside a script tag on the front end without adequate sanitization. The injected code executes for visitors and for Editors or Administrators who review the post. The authoritative export does not name the save endpoint, parameter, or rendering function.

PublishedSep 11, 2026
Known safe version2.7.8
Published vulnerabilities for ai-builder
Safe version
Sep 11, 2026 CVE-2026-85678
AI Builder permits contributor stored JavaScript
AI Builder before 2.7.8 lets Contributors save custom JavaScript against a post and echoes that value inside a script tag on the front end without adequate sanitization. The injected code executes for visitors and for Editors or Administrators who review the post. The authoritative export does not name the save endpoint, parameter, or rendering function.
2.7.8
CVE6.8
NVDPending