PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-96871 kitae-park CVE debrief

The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards. Defenders should prioritize verifying and updating the Mang Board plugin to prevent exploitation of this vulnerability.

Vendor
kitae-park
Product
Mang Board
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-02
Original CVE updated
2026-10-03
Advisory published
2026-10-02
Advisory updated
2026-10-03

Who should care

Defenders responsible for WordPress sites using the Mang Board plugin should assess exposure and prioritize updating the plugin to prevent exploitation. This includes reviewing board configurations to ensure write_level and editor_type settings are secure. Additionally, defenders should monitor for suspicious activity on WordPress sites using the Mang Board plugin and perform a thorough review of all boards created with the Mang Board plugin to identify

Why it matters

The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting, allowing unauthenticated attackers to inject arbitrary web scripts. Defenders should prioritize verifying and updating the plugin to prevent exploitation.

  • Unauthenticated attackers can inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page
  • Exploitation requires default board configurations (write_level=0 and editor_type=N)
  • Verification of plugin version and board configurations is necessary to prevent exploitation
  • Remediation priority is high due to the potential for unauthenticated attacks

Technical summary

The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2. This vulnerability is caused by insufficient input sanitization and output escaping. An unauthenticated attacker can exploit this vulnerability by injecting arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability requires default board configurations (write_level=0 and editor_type=N) to be exploitable, which are the out-of-the-box defaults for newly created boards.

Defensive priority

Defenders should prioritize verifying and updating the Mang Board plugin to prevent exploitation of this vulnerability.

Recommended defensive actions

  • Verify the Mang Board plugin version and update to a patched version if necessary
  • Review board configurations to ensure write_level and editor_type settings are secure
  • Monitor for suspicious activity on WordPress sites using the Mang Board plugin
  • Perform a thorough review of all boards created with the Mang Board plugin to identify potential exposure
  • Prioritize updating the Mang Board plugin to prevent exploitation of this vulnerability
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards. Exploitability requires no authentication and is contingent on these default settings being present. Defenders should verify plugin version and board configurations to ensure they are not exposed to unauthenticated attacks. Evidence from the Mang Board plugin code and CVE record supports this assessment.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-96871 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-96871

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-96871 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96871

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.