high · CVSS v3 7.2 · EPSS 0.00241
CVE-2026-96871
The Mang Board plugin for WordPress has a stored XSS vulnerability in the data_type parameter. Unauthenticated attackers can inject scripts
Overview
The Mang Board plugin for WordPress has a stored XSS vulnerability in the data_type parameter. Unauthenticated attackers can inject scripts that run when users view affected pages. This can lead to session hijacking or defacement.
Description
The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards.
Impact
Confidentiality: attackers can steal user data via injected scripts. Integrity: content can be altered. Availability: minimal. Affects all WordPress sites using Mang Board with default guest posting settings.
Remediation
Update Mang Board to version 2.4.3 or later. If update not possible, restrict write_level to 1 or higher, disable guest posting, and sanitize data_type input. Use a web application firewall to block XSS payloads.
Risk context
High severity but low predicted exploitation probability (EPSS 0.00241). Immediate patch recommended for sites with guest posting enabled.
Affected products
- WordPress
- Mang Board plugin
- Mang Board 2.4.2
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00241