Authorization Flaw in HootBoard WordPress Plugin Exposes Users to Script Injection
CVE-2026-86798
Currently unrated
Key Information:
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-86798?
The HootBoard WordPress plugin, specifically version 3.1.4, exposes a vulnerability that lacks proper authorization checks on several REST endpoints. This oversight allows unauthenticated users to inject arbitrary web scripts, which are subsequently executed in the browsers of any individuals visiting the affected public page, including site administrators. The plugin also fails to sanitize input values before displaying them, further heightening the risk of exploitation and potential data manipulation.
Affected Version(s)
HootBoard 0 <= 3.1.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.