Description
The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards.
Published: 2026-10-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross-Site Scripting
Action: Patch Now
AI Analysis

Impact

The vulnerability allows an attacker to store malicious JavaScript in the 'data_type' parameter of Mang Board, which is then rendered on board pages without sanitization or escaping. A successful injection grants the attacker the ability to execute arbitrary scripts in the browsers of any user who visits the infected page, enabling theft of session data, defacement, or further malicious payload delivery.

Affected Systems

This issue affects installations of the Mang Board WordPress plugin from any version up to and including 2.4.2. The attack is possible when the board is configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the prevailing defaults for newly created boards.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the injection vector is unauthenticated and relies on standard board configuration, the risk is elevated for sites that allow guest posting. An attacker can compromise any visitor’s browser that views an infected page.

Generated by OpenCVE AI on October 2, 2026 at 08:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Mang Board to a version later than 2.4.2 or remove the plugin entirely.
  • If an upgrade is not immediately possible, disable guest posting by setting write_level to a value greater than 0 or changing editor_type from N to a stricter mode.
  • Ensure that any form or API that accepts the 'data_type' value performs proper input validation and output escaping to eliminate stored XSS vectors.

Generated by OpenCVE AI on October 2, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards.
Title Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_type' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:26.671Z

Reserved: 2026-09-23T18:13:18.413Z

Link: CVE-2026-96871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:04.813

Modified: 2026-10-02T08:17:04.813

Link: CVE-2026-96871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')