rootpwn

high · CVSS v3 7.2 · EPSS 0.00241

CVE-2026-96871

The Mang Board plugin for WordPress has a stored XSS vulnerability in the data_type parameter. Unauthenticated attackers can inject scripts

Overview

The Mang Board plugin for WordPress has a stored XSS vulnerability in the data_type parameter. Unauthenticated attackers can inject scripts that run when users view affected pages. This can lead to session hijacking or defacement.

Description

The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards.

Impact

Confidentiality: attackers can steal user data via injected scripts. Integrity: content can be altered. Availability: minimal. Affects all WordPress sites using Mang Board with default guest posting settings.

Remediation

Update Mang Board to version 2.4.3 or later. If update not possible, restrict write_level to 1 or higher, disable guest posting, and sanitize data_type input. Use a web application firewall to block XSS payloads.

Risk context

High severity but low predicted exploitation probability (EPSS 0.00241). Immediate patch recommended for sites with guest posting enabled.

Affected products

  • WordPress
  • Mang Board plugin
  • Mang Board 2.4.2

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00241

XSS WordPress Stored XSS Guest Posting Mang Board High Severity Web Application

← All CVEs