Impact
The KBoard plugin before version 6.7 fails to verify ownership or context when deleting board media, allowing unauthenticated attackers to permanently delete uploaded media files and their database records by iterating identifiers. This flaw results in loss of data integrity and potential site downtime.
Affected Systems
All WordPress installations using the KBoard plugin at or below version 6.6 are affected. Any site with the vulnerable media deletion endpoint exposed to the public is at risk.
Risk and Exploitability
The EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not listed in CISA KEV. Because the flaw permits deletion without authentication, an attacker can remove critical content and database entries through simple HTTP requests to the deletion endpoint, making the risk significant despite the low exploitation likelihood.
OpenCVE Enrichment