Junglewise Threat Intelligence

CVE-2026-75977: Mang Board WP authentication cookie forgery

CVE-2026-75977 · Severity: high · CVSS 8.8 · Published 2026-08-26

Technologies: Mang Board WP.

Executive brief

Mang Board WP is a WordPress plugin that provides forum functionality. The plugin incorrectly generates authentication cookies, allowing users with basic subscriber access to forge administrator credentials and take over WordPress sites. An attacker can change admin passwords and gain full control without higher-level permissions.

Technical details

The vulnerability is an authentication bypass via cookie forgery, stemming from flawed HMAC generation in the mbw_get_hash_key() function. When a WordPress user is logged in, the function uses the current user's identity instead of the cookie username parameter when computing the HMAC, combined with insufficient validation in mbw_validate_auth_cookie(). This allows authenticated attackers with subscriber-level or higher privileges to craft valid administrator authentication cookies. The attack requires an authenticated session but does not require user interaction; an attacker can forge cookies and escalate to full site control by changing administrator passwords.

Affected products

  • Mang Board WP Mang Board WP up to and including 2.3.7

Timeline

  • 2026-08-26: disclosed

References