ZeroHour

CVE-2026-84770

niche

Unauthenticated CSRF in Mang Board WP WordPress Plugin

CVSS 3.1
8.8 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-84770 is a cross-site request forgery (CSRF) flaw in the Mang Board WP WordPress plugin that allows unauthenticated attackers to trigger actions because requests are not validated with a CSRF-protection token. It is triggered when a logged-in WordPress user, such as an administrator, is deceived into opening a malicious link or page while the attacker's forged request executes against the affected site. A successful attack can cause unauthorized changes with high impact to confidentiality, integrity, and availability, as reflected in the 8.8 (High) CVSS 3.1 score. Any WordPress installation running Mang Board WP version 2.3.8 or earlier is affected. No public proof of concept, CISA KEV listing, or confirmed exploitation activity is currently known.

What to do: Update Mang Board WP to the newest release available from the WordPress plugin directory (any version newer than 2.3.8) as soon as a patched release is confirmed. Until then, avoid following untrusted links while logged into sites running the plugin and verify that any unexpected site changes have not occurred. Administrators should confirm their installed plugin version and monitor the vendor or Patchstack for a fix.

Affected
Mang Board (WordPress plugin) Mang Board WP<= 2.3.8
Estimated exposure
nichelikely a few hundred to low thousands of WordPress sites (niche Korean-language board plugin) — Mang Board WP is a niche, primarily Korean-market bulletin board plugin with a small active-install footprint compared to mainstream WordPress plugins, so exposure is estimated in the hundreds of sites, though exact active-install counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.

Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.