Description
The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a public page, allowing unauthenticated users to inject arbitrary web scripts that will execute in the browser of anyone visiting that page, including administrators.
Published: 2026-10-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting without authentication on the HootBoard WordPress plugin
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the HootBoard WordPress plugin allows an attacker to submit data through unsecured REST endpoints that are not protected by an authorization check. The data stored by these endpoints is subsequently rendered on a public page without any escaping, enabling arbitrary JavaScript to be injected. Because the script runs in the context of any visitor, an attacker could hijack sessions, steal credentials, deface pages, or perform further malicious actions as the site administrator.

Affected Systems

All WordPress sites that have the HootBoard plugin installed with a version through 3.1.4 are affected. The issue is present in the plugin’s configuration REST endpoint, and no vendor version beyond 3.1.4 has been specified as vulnerable in the current disclosure.

Risk and Exploitability

The vulnerability is a significant risk due to its lack of authentication and its potential to compromise any user who views the affected page, including administrators. No EPSS score is available and the flaw is not listed in CISA’s KEV catalog, but the description indicates that the flaw can be exploited by unauthenticated users. The absence of an EPSS value means that built‑in exploitation probability estimates are not currently available, yet the documented flaw suggests a high likelihood of exploitation if the plugin is not patched. The CVSS score is not provided in the disclosure, so a formal severity assessment is unavailable; however, the nature of the flaw warrants a high‑severity response.

Generated by OpenCVE AI on October 11, 2026 at 07:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the HootBoard plugin to the latest version (3.1.5 or newer) where the REST endpoint authorization and data sanitization fixes are applied.
  • If an upgrade cannot be performed immediately, restrict the vulnerable REST endpoints to authenticated roles only, or disable them from the WordPress site configuration.
  • Ensure that any input stored by the plugin is properly escaped before rendering, using WordPress sanitization functions such as esc_html() or esc_js(), to mitigate the XSS vector if the plugin does not handle it internally.

Generated by OpenCVE AI on October 11, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-79

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a public page, allowing unauthenticated users to inject arbitrary web scripts that will execute in the browser of anyone visiting that page, including administrators.
Title HootBoard <= 3.1.4 - Unauthenticated Stored XSS via Board Configuration REST Endpoint
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:43.752Z

Reserved: 2026-09-08T12:17:03.280Z

Link: CVE-2026-86798

cve-icon Vulnrichment

Updated: 2026-10-11T11:22:19.363Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:26.450

Modified: 2026-10-11T12:17:24.800

Link: CVE-2026-86798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:45:18Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')