Impact
The vulnerability allows an attacker to store malicious JavaScript in the 'data_type' parameter of Mang Board, which is then rendered on board pages without sanitization or escaping. A successful injection grants the attacker the ability to execute arbitrary scripts in the browsers of any user who visits the infected page, enabling theft of session data, defacement, or further malicious payload delivery.
Affected Systems
This issue affects installations of the Mang Board WordPress plugin from any version up to and including 2.4.2. The attack is possible when the board is configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the prevailing defaults for newly created boards.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the injection vector is unauthenticated and relies on standard board configuration, the risk is elevated for sites that allow guest posting. An attacker can compromise any visitor’s browser that views an infected page.
OpenCVE Enrichment