Sceawere

Vulnerability Detail

CVE-2026-96871UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Mang Board Stored XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
15h ago
Vendor
kitae-park
Product
Mang Board
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T08:17:04.813Z",
  "pubdate": "2026-10-02T08:17:04.813Z",
  "executiveSummary": "The Mang Board plugin for WordPress, in all versions up to and including 2.4.2, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability stems from inadequate sanitization of user-supplied input within the 'data_type' parameter, coupled with a lack of proper output encoding.\nAn unauthenticated attacker can leverage this flaw to inject malicious JavaScript into the application, which executes within the context of an unsuspecting user's browser session upon viewing the compromised page.\nThe vulnerability is exploitable by default configurations where boards permit guest submissions (write_level=0) and utilize the default editor type (editor_type=N).\nSuccessful exploitation facilitates unauthorized actions performed on behalf of authenticated users, potential session hijacking, and the exfiltration of sensitive information.\nGiven the default configuration parameters, the attack surface is significantly broad for newly initialized boards, posing a critical risk to site integrity and user security.",
  "technicalDetails": "The vulnerability originates from the improper handling of the 'data_type' parameter within the Mang Board plugin. The plugin fails to apply robust server-side input sanitization or context-aware output escaping when processing this parameter, allowing arbitrary data to be persisted to the WordPress database.\nThe attack flow commences when an unauthenticated threat actor interacts with a board configured with default settings, specifically write_level=0 and editor_type=N. These settings permit guest users to submit content without administrative oversight or session authentication.\nBy crafting a malicious payload containing JavaScript, an attacker can submit this string through the 'data_type' parameter. Because the application blindly stores this input, the payload is persisted in the database associated with the board entry.\nWhen a legitimate user or administrator subsequently navigates to the affected page, the plugin retrieves the malicious payload from the database and renders it directly into the HTML document structure without escaping characters such as '<', '>', or quotes. Consequently, the browser interprets the injected script as valid code rather than plain text.\nThe scope of the impact includes, but is not limited to, the execution of arbitrary scripts in the victim's browser session. This can be weaponized to perform unauthorized operations, such as modifying administrative configurations, stealing session cookies (Session Hijacking), or redirecting users to malicious external domains.\nThe exposure is exacerbated by the plugin's default installation state. As the vulnerable board settings are the out-of-the-box defaults, any instance of Mang Board that has not been specifically hardened remains immediately vulnerable to remote exploitation. The combination of unauthenticated access and the lack of parameter validation creates a high-severity entry point for attackers to achieve persistent code execution within the context of the WordPress domain."
}
CVE-2026-96871: Mang Board Stored XSS Vulnerability (HIGH Severity, CVSS: 7.2) | Sceawere