CVE-2026-94176: WordPress Mang Board WP plugin <= 2.4.1 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Mang Board WP pluginto a version that resolves this vulnerability.Fixed in 2.4.2
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges. Exploitation requires user interaction, as indicated by the UI:R vector.
Which installations are affected?
Mang Board WP versions 2.4.1 and earlier are identified as affected. The provided data does not state whether any particular WordPress configuration or plugin feature must be enabled.
What is the potential impact if exploitation succeeds?
The supplied vector indicates low confidentiality, integrity, and availability impact, with scope changed. Because this is XSS, the practical impact depends on a user interacting with attacker-controlled script content.