{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-96871/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:mang_board:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96871"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mang Board (\u003c= 2.4.2)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","wordpress","cve-2026-96871"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Mang Board plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-96871, impacting all versions up to and including 2.4.2. The vulnerability arises from insufficient input sanitization and output escaping on the 'data_type' parameter. Because the plugin defaults to guest posting ('write_level=0') and 'editor_type=N' for new boards, the attack vector is exposed to unauthenticated users out-of-the-box. Successful exploitation enables an attacker to inject arbitrary JavaScript into boards, which subsequently executes in the browsers of users viewing the content. This poses a significant risk to administrative sessions and user data within the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running an vulnerable version of the Mang Board plugin.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with a publicly accessible board hosted by the plugin.\u003c/li\u003e\n\u003cli\u003eAttacker submits a POST request to the plugin endpoint containing a malicious payload in the 'data_type' parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to sanitize the input and saves the payload directly into the database.\u003c/li\u003e\n\u003cli\u003eThe server stores the malicious script within the board's data structure.\u003c/li\u003e\n\u003cli\u003eA victim user (such as an administrator or other user) browses to the compromised page.\u003c/li\u003e\n\u003cli\u003eThe WordPress site serves the page containing the attacker's stored script.\u003c/li\u003e\n\u003cli\u003eThe victim's browser executes the script in the context of the site, leading to session hijacking or unauthorized actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browsers of visitors. This can result in session hijacking, the theft of sensitive session cookies, unauthorized administrative actions performed on behalf of logged-in users, or the redirection of users to malicious websites. The vulnerability is particularly severe due to the default configuration of the plugin, which permits unauthenticated guest posting on newly created boards.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize updating the Mang Board plugin to the latest available version that patches CVE-2026-96871. If patching is not immediately feasible, modify the board settings to disable 'write_level=0' (guest posting) or change the 'editor_type' to a restricted mode to limit the exposure of the vulnerable input parameter. Implement a Content Security Policy (CSP) to mitigate the impact of XSS vulnerabilities by restricting the sources from which scripts can be loaded and executed.\u003c/p\u003e\n","date_modified":"2026-10-02T08:24:31Z","date_published":"2026-10-02T08:24:31Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mang-board-xss/","summary":"The Mang Board plugin for WordPress (\u003c= 2.4.2) is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the 'data_type' parameter, allowing attackers to inject malicious scripts that execute in the context of user browsers.","title":"Stored XSS in Mang Board Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-mang-board-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-96871","version":"https://jsonfeed.org/version/1.1"}