Impact
The vulnerability is an unauthenticated Cross‑Site Scripting flaw in the Mang Board WP plugin. An attacker can inject malicious scripts into pages served by the plugin, potentially stealing session cookies or executing arbitrary client‑side code. The impact is limited to client‑side code execution; it does not allow direct server compromise or remote code execution on the WordPress host.
Affected Systems
WordPress sites running the Mang Board WP plugin version 2.3.4 or earlier. All installations of this plugin are affected until upgraded to 2.3.5 or later. The vendor is Kitae Park, the affected product is the Mang Board WP plugin.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of the issue. The EPSS score is unavailable, but because the flaw is unauthenticated and relies solely on client‑side injection, it could be exploited by any user visiting the vulnerable site. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation at the time of this analysis. The likely attack vector is remote, via a crafted URL or embedded script that the victim subsequently browsers, leading to client‑side code execution or session hijacking.
OpenCVE Enrichment