Description
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
Published: 2026-08-13
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross‑Site Scripting flaw in the Mang Board WP plugin. An attacker can inject malicious scripts into pages served by the plugin, potentially stealing session cookies or executing arbitrary client‑side code. The impact is limited to client‑side code execution; it does not allow direct server compromise or remote code execution on the WordPress host.

Affected Systems

WordPress sites running the Mang Board WP plugin version 2.3.4 or earlier. All installations of this plugin are affected until upgraded to 2.3.5 or later. The vendor is Kitae Park, the affected product is the Mang Board WP plugin.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity of the issue. The EPSS score is unavailable, but because the flaw is unauthenticated and relies solely on client‑side injection, it could be exploited by any user visiting the vulnerable site. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation at the time of this analysis. The likely attack vector is remote, via a crafted URL or embedded script that the victim subsequently browsers, leading to client‑side code execution or session hijacking.

Generated by OpenCVE AI on August 13, 2026 at 15:54 UTC.

Remediation

Vendor Solution

Update the WordPress Mang Board WP Plugin to the latest available version (at least 2.3.5).


OpenCVE Recommended Actions

  • Update the Mang Board WP plugin to at least version 2.3.5
  • If the plugin is not needed, remove or disable it from the WordPress installation
  • Review and ensure that all user‑submitted content is properly encoded before rendering to prevent future XSS

Generated by OpenCVE AI on August 13, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Kitae-park
Kitae-park mang Board Wp
Wordpress
Wordpress wordpress
Vendors & Products Kitae-park
Kitae-park mang Board Wp
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
Title WordPress Mang Board WP plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Kitae-park Mang Board Wp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:14:41.657Z

Reserved: 2026-07-13T06:13:55.443Z

Link: CVE-2026-61974

cve-icon Vulnrichment

Updated: 2026-08-13T15:14:37.176Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:03.210

Modified: 2026-08-13T16:18:15.763

Link: CVE-2026-61974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')