Sceawere
Vulnerability Detail
CVE-2026-86798UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HootBoard Unauthenticated Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- HootBoard
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a public page, allowing unauthenticated users to inject arbitrary web scripts that will execute in the browser of anyone visiting that page, including administrators.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-11T07:17:26.450Z",
"pubdate": "2026-10-11T07:17:26.450Z",
"executiveSummary": "The HootBoard WordPress plugin, in versions through 3.1.4, contains a critical security vulnerability characterized as a Stored Cross-Site Scripting (XSS) flaw. The vulnerability stems from a lack of authorization checks and insufficient input sanitization within the plugin's REST API endpoints.\nThis vulnerability allows unauthenticated, remote attackers to inject arbitrary JavaScript payloads into the HootBoard system. Because the stored data is rendered on public-facing pages without proper output encoding, the injected scripts execute automatically in the context of any user visiting the affected page, including high-privileged administrator accounts.\nThe primary risk implication is the potential for full administrative account compromise, session hijacking, redirection to malicious domains, or unauthorized modification of site content. As the exploitation does not require prior authentication or elevated privileges, the attack surface is exposed to any network-capable threat actor. The impact is considered high, as it facilitates unauthorized control over the WordPress environment by leveraging the trust relationship between the administrator's browser and the affected web application.",
"technicalDetails": "The root cause of this vulnerability is a failure in the plugin's REST API implementation to enforce access control lists (ACLs) or authentication requirements on specific endpoints. By design, these endpoints permit the submission of data that is subsequently persisted within the WordPress database without undergoing rigorous sanitization or validation routines.\nThe exploitation flow begins with an unauthenticated attacker sending a crafted POST or PUT request to the exposed HootBoard REST API endpoint. The request payload includes a malicious JavaScript snippet disguised as legitimate data. Since the vulnerable component lacks server-side authorization checks, the application processes the input and stores the unsanitized script directly into the database.\nThe secondary phase of the attack occurs during the rendering cycle. When a user—such as an unprivileged visitor or a site administrator—navigates to a page where HootBoard displays the stored content, the application echoes the malicious payload directly into the HTML document object model (DOM) without applying appropriate output encoding or context-aware escaping. Consequently, the browser interprets the injected script as valid code and executes it within the security context of the victim's session.\nThe impact of this execution is significant: the script can access the browser's cookies, local storage, and session tokens, facilitating session hijacking. Furthermore, the script can perform background requests on behalf of the victim (Cross-Site Request Forgery), allowing an attacker to modify site settings, create new administrative users, or inject additional persistent backdoors. Because the script runs in the administrator's browser, the attacker can effectively bypass server-side security controls, turning a client-side vulnerability into full-site exploitation.\nAffected versions are identified as HootBoard through 3.1.4. The vulnerability is categorized by the lack of REST API permission checks and the absence of output filtering, which together violate standard secure coding practices regarding untrusted user input handling."
}