CVE-2026-88910: KBoard < 6.7 - Unauthenticated Board Media Deletion via IDOR
Published Sep 16, 2026
·Updated
The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers.
Event History
Sep 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
WordPress sites using the KBoard plugin version 6.6 or earlier are affected. The issue concerns media uploaded through KBoard boards.
2
What does an attacker need to exploit it?
No authentication is required. An attacker can iterate media identifiers to target uploaded board media for deletion.
3
What is the impact of successful exploitation?
An attacker can permanently delete KBoard-uploaded media files and their associated database records. This can cause irreversible loss of board media content.