Impact
The vulnerability in the Mang Board WP plugin allows an attacker to submit state‑changing requests in the victim’s session without authentication, because the plugin does not validate an authenticity token for privileged actions. This can lead to unauthorized changes to site content or configuration, compromising the integrity of the website. The impact is limited to actions that the authenticated user is allowed to perform, but the absence of protection can enable attackers to alter or delete data, inject content, or change settings, undermining confidentiality and integrity of the site.
Affected Systems
WordPress installations that have the Mang Board WP plugin version 2.3.8 or older are affected. The plugin, developed by Kitae Park, is included in WordPress sites that rely on the plugin for its board functionality. Identified versions are all releases up to and including 2.3.8.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. The EPSS score is not available, but the lack of an authentication requirement coupled with a low complexity of attack suggests a high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would typically need a victim who is logged into the site; the attacker only needs to send a crafted CSRF request, such as a link or form submission, to trigger the privileged action. No additional prerequisites are documented.
OpenCVE Enrichment