Skip to content
Threat Feed
high advisory

Stored XSS in Mang Board Plugin for WordPress

The Mang Board plugin for WordPress (<= 2.4.2) is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the 'data_type' parameter, allowing attackers to inject malicious scripts that execute in the context of user browsers.

CVE search metadata

CVE search record: CVE-2026-96871. Severity: high. CVSS: 7.2. KEV: no. Product: Mang Board (<= 2.4.2). Brief: Stored XSS in Mang Board Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-mang-board-xss/

The Mang Board plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-96871, impacting all versions up to and including 2.4.2. The vulnerability arises from insufficient input sanitization and output escaping on the 'data_type' parameter. Because the plugin defaults to guest posting ('write_level=0') and 'editor_type=N' for new boards, the attack vector is exposed to unauthenticated users out-of-the-box. Successful exploitation enables an attacker to inject arbitrary JavaScript into boards, which subsequently executes in the browsers of users viewing the content. This poses a significant risk to administrative sessions and user data within the WordPress environment.

Attack Chain

  1. Attacker identifies a WordPress site running an vulnerable version of the Mang Board plugin.
  2. Attacker interacts with a publicly accessible board hosted by the plugin.
  3. Attacker submits a POST request to the plugin endpoint containing a malicious payload in the 'data_type' parameter.
  4. The plugin fails to sanitize the input and saves the payload directly into the database.
  5. The server stores the malicious script within the board's data structure.
  6. A victim user (such as an administrator or other user) browses to the compromised page.
  7. The WordPress site serves the page containing the attacker's stored script.
  8. The victim's browser executes the script in the context of the site, leading to session hijacking or unauthorized actions.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browsers of visitors. This can result in session hijacking, the theft of sensitive session cookies, unauthorized administrative actions performed on behalf of logged-in users, or the redirection of users to malicious websites. The vulnerability is particularly severe due to the default configuration of the plugin, which permits unauthenticated guest posting on newly created boards.

Recommendation

Prioritize updating the Mang Board plugin to the latest available version that patches CVE-2026-96871. If patching is not immediately feasible, modify the board settings to disable 'write_level=0' (guest posting) or change the 'editor_type' to a restricted mode to limit the exposure of the vulnerable input parameter. Implement a Content Security Policy (CSP) to mitigate the impact of XSS vulnerabilities by restricting the sources from which scripts can be loaded and executed.


Immediate actions

Patch Mang Board plugin to the latest version to address CVE-2026-96871.

IT Operations 48h

Mitigations

Change default board configuration: set write_level > 0 to prevent guest posting.

immediate IT Operations

CVE-2026-96871

Detection coverage 1

Detect CVE-2026-96871 Exploitation - POST Request with Script Tags in data_type Parameter

high

Detects potential exploitation of CVE-2026-96871 by monitoring for HTTP POST requests to the web server that contain script tags within the 'data_type' parameter.

sigma tactics: initial_access techniques: T1059.007 sources: webserver

Detection queries are available on the platform. Get full rules →