PatchSiren cyber security CVE debrief
CVE-2026-96871 kitae-park CVE debrief
The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards. Defenders should prioritize verifying and updating the Mang Board plugin to prevent exploitation of this vulnerability.
- Vendor
- kitae-park
- Product
- Mang Board
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-02
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-02
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for WordPress sites using the Mang Board plugin should assess exposure and prioritize updating the plugin to prevent exploitation. This includes reviewing board configurations to ensure write_level and editor_type settings are secure. Additionally, defenders should monitor for suspicious activity on WordPress sites using the Mang Board plugin and perform a thorough review of all boards created with the Mang Board plugin to identify
Why it matters
The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting, allowing unauthenticated attackers to inject arbitrary web scripts. Defenders should prioritize verifying and updating the plugin to prevent exploitation.
- Unauthenticated attackers can inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page
- Exploitation requires default board configurations (write_level=0 and editor_type=N)
- Verification of plugin version and board configurations is necessary to prevent exploitation
- Remediation priority is high due to the potential for unauthenticated attacks
Technical summary
The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2. This vulnerability is caused by insufficient input sanitization and output escaping. An unauthenticated attacker can exploit this vulnerability by injecting arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability requires default board configurations (write_level=0 and editor_type=N) to be exploitable, which are the out-of-the-box defaults for newly created boards.
Defensive priority
Defenders should prioritize verifying and updating the Mang Board plugin to prevent exploitation of this vulnerability.
Recommended defensive actions
- Verify the Mang Board plugin version and update to a patched version if necessary
- Review board configurations to ensure write_level and editor_type settings are secure
- Monitor for suspicious activity on WordPress sites using the Mang Board plugin
- Perform a thorough review of all boards created with the Mang Board plugin to identify potential exposure
- Prioritize updating the Mang Board plugin to prevent exploitation of this vulnerability
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards. Exploitability requires no authentication and is contingent on these default settings being present. Defenders should verify plugin version and board configurations to ensure they are not exposed to unauthenticated attacks. Evidence from the Mang Board plugin code and CVE record supports this assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-96871 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-96871
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-96871 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96871
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/mangboard/tags/2.4.2/includes/functions/func.api.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/mangboard/tags/2.4.2/includes/mb-actions.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/mangboard/tags/2.4.2/includes/skin-filters.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.