Impact
The Mang Board WP plugin contains an authorization flaw that lets attackers who already have subscriber-level or higher privileges forge administrator authentication cookies. The flaw stems from HMAC key generation that uses the current user’s identity instead of the cookie username parameter, combined with insufficient validation in the cookie verification routine. Consequently, a crafted cookie can impersonate an administrator, allowing the attacker to change the admin password and assume full control of the WordPress site.
Affected Systems
All installations of the Mang Board WP plugin version 2.3.7 or earlier from the vendor kitae-park are affected. Any site running these versions with the plugin active is vulnerable, including releases 2.3.5 and 2.3.6 that contain the same code.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. Exploitation requires an authenticated user with subscriber or higher access, after which forging a cookie and taking over the site is straightforward. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of an EPSS metric does not reduce the high impact of the flaw.
OpenCVE Enrichment