CVE-2026-86798
Received Received - Intake

Unauthenticated Stored Cross-Site Scripting in HootBoard WordPress Plugin

Vulnerability report for CVE-2026-86798, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a public page, allowing unauthenticated users to inject arbitrary web scripts that will execute in the browser of anyone visiting that page, including administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown HootBoard 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated stored cross-site scripting (XSS) flaw in the HootBoard WordPress plugin versions up to 3.1.4. It allows attackers to inject malicious scripts into public pages without authentication. The scripts execute in the browsers of visitors, including administrators, when they view the affected page.

Detection Guidance

Check if the HootBoard WordPress plugin version 3.1.4 or below is installed. Inspect network traffic for unauthenticated requests to the Board Configuration REST endpoint. Look for stored XSS payloads in public pages rendered by the plugin.

Impact Analysis

Unauthenticated attackers can inject malicious scripts that execute in the browsers of anyone visiting the affected page. This could lead to theft of session cookies, account takeover, or defacement of the website. Administrators are particularly at risk as their elevated access could be exploited.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations may face fines or penalties for failing to protect user data adequately.

Mitigation Strategies

Immediately update the HootBoard plugin to the latest version if available. If no update exists, disable or remove the plugin until a patch is released. Monitor for suspicious activity or unauthorized script injections in public pages.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86798. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart