Authorization Flaw in HootBoard WordPress Plugin Exposes Users to Script Injection
CVE-2026-86798

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
11 October 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-86798?

The HootBoard WordPress plugin, specifically version 3.1.4, exposes a vulnerability that lacks proper authorization checks on several REST endpoints. This oversight allows unauthenticated users to inject arbitrary web scripts, which are subsequently executed in the browsers of any individuals visiting the affected public page, including site administrators. The plugin also fails to sanitize input values before displaying them, further heightening the risk of exploitation and potential data manipulation.

Affected Version(s)

HootBoard 0 <= 3.1.4

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pablo González Pérez
Francisco José Ramírez Vicente
and Iñigo Sánchez Enciso
WPScan
.