PatchSiren

HootBoard CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review HootBoard CVE published 2026-10-11

CVE-2026-86798

The HootBoard WordPress plugin through 3.1.4 has REST endpoints that lack authorization checks and do not escape stored values before outputting them in a public page. This allows unauthenticated users to inject arbitrary web scripts that execute in the browser of anyone visiting that page, including administrators. The vulnerability is particularly concerning because it can be exploited by unauthenticate [truncated]