CVE-2026-75977: Mang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie

Published Aug 26, 2026
·
Updated

The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbwgethashkey() function that uses the current user's identity instead of the cookie username parameter when a WordPress user is logged in, combined with insufficient validation in mbwvalidateauthcookie(). This makes it possible for authenticated attackers, with subscriber-level access and above, to forge administrator authentication cookies and change administrator passwords to achieve complete site takeover.

Affected Software

1 affected component
WordPress Mang Board WP plugin<=2.3.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Mang Board WP (WordPress plugin) to a version that resolves this vulnerability.

    Fixed in 2.3.7
  2. Configuration

    Upgrade the Mang Board WP plugin to a version where the Missing Authorization via Authentication Cookie Forgery issue is fixed (vulnerable in all versions up to and including 2.3.7).

    WordPress Authentication cookie forging mitigation (Missing Authorization via Authentication Cookie Forgery) = Apply Mang Board WP patch/fix for versions > 2.3.7

Event History

Aug 26, 2026
CVE Published
via MITRE·07:42 AM
Data Sourced
via MITRE·07:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Can exploitation be performed remotely without user interaction?

Yes. The CVSS vector indicates network-based exploitation with low attack complexity and no user interaction, but the attacker must first have an authenticated WordPress account with at least Subscriber-level access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203