CVE-2026-75977
Received Received - Intake

Authentication Cookie Forgery in Mang Board WP Plugin

Vulnerability report for CVE-2026-75977, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: Wordfence

Description

The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbw_get_hash_key() function that uses the current user's identity instead of the cookie username parameter when a WordPress user is logged in, combined with insufficient validation in mbw_validate_auth_cookie(). This makes it possible for authenticated attackers, with subscriber-level access and above, to forge administrator authentication cookies and change administrator passwords to achieve complete site takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mang_board wp_plugin to 2.3.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Mang Board WP plugin for WordPress has a vulnerability due to flawed HMAC generation in the mbw_get_hash_key() function. It uses the current user's identity instead of the cookie username parameter when a user is logged in. This, combined with insufficient validation in mbw_validate_auth_cookie(), allows authenticated attackers with subscriber-level access or higher to forge administrator authentication cookies and change administrator passwords, leading to complete site takeover.

Impact Analysis

This vulnerability allows attackers to gain full control of a WordPress site by forging administrator authentication cookies and resetting passwords. Attackers only need subscriber-level access or higher to exploit it, which could lead to unauthorized changes, data theft, or site disruption.

Mitigation Strategies

Update the Mang Board WP plugin to the latest version beyond 2.3.7 to fix the authorization flaw. Remove or disable the plugin if no update is available. Review user accounts for unauthorized changes and reset administrator passwords.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75977. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart