Review
HootBoard
CVE published 2026-10-11
CVE-2026-86798
The HootBoard WordPress plugin through 3.1.4 has REST endpoints that lack authorization checks and do not escape stored values before outputting them in a public page. This allows unauthenticated users to inject arbitrary web scripts that execute in the browser of anyone visiting that page, including administrators. The vulnerability is particularly concerning because it can be exploited by unauthenticate [truncated]