Junglewise Threat Intelligence

CVE-2026-13334: kitae-park Mang Board WP reflected XSS in stag parameter

CVE-2026-13334 · Severity: medium · CVSS 6.1 · Published 2026-07-09

Technologies: Kitae-Park Mang Board WP. Vendors: Kitae-Park.

Executive brief

The Mang Board WP plugin for WordPress, which provides bulletin board and store functionality, contains a security flaw that allows attackers to run malicious scripts in a user's browser. To exploit this, an attacker must trick a site visitor or administrator into clicking a specially crafted link. If successful, this could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Mang Board WP plugin for WordPress due to improper neutralization of the 'stag' input parameter. The vulnerability is located across several components, including the store class and basic skin headers, where user-supplied data is reflected back into the application's HTML without adequate sanitization or output escaping. An unauthenticated attacker can exploit this by crafting a malicious URL containing a script payload and persuading a victim to visit it. Successful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's browser session. The issue affects all versions up to and including 2.3.4.

Affected products

  • kitae-park Mang Board WP up to, and including, 2.3.4

Timeline

  • 2026-07-09: advisory: Wordfence published the vulnerability advisory.
  • 2026-07-09: disclosed: CVE-2026-13334 was published to the NVD.

References