Impact
Unauthenticated Cross Site Scripting allows an attacker to inject arbitrary script code into pages generated by the Mang Board WP plugin. The lack of proper input validation and sanitization (CWE‑79) enables a malicious user to execute scripts in the browser of any person who views the affected page. This can lead to session hijacking, credential theft, or defacement of the site. The vulnerability directly compromises the confidentiality and integrity of user data and the availability of site content if used for phishing.
Affected Systems
The vulnerability is present in the WordPress Mang Board WP plugin by Kitae Park, affecting all installations using version 2.4.1 or earlier. Upgrading to 2.4.2 or later removes the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high risk, and although an EPSS score is not available, the lack of authentication requirement suggests a high likelihood of exploitation in environments where the plugin is publicly accessible. The plug‑in is not listed in the CISA KEV catalog, but its unauthenticated nature means any WordPress site using the vulnerable version can be exploited without special conditions.
OpenCVE Enrichment