Executive brief
Mang Board WP is a WordPress plugin used to create discussion boards and community forums on WordPress sites. An unauthenticated attacker can trick a logged-in site administrator or user into performing unintended actions (such as changing settings, deleting content, or modifying accounts) by crafting a malicious webpage or link. This could lead to unauthorized modifications, account compromise, or site disruption depending on the victim's privilege level.
Technical details
This vulnerability is a Cross-Site Request Forgery (CSRF) flaw in the Mang Board WP plugin versions up to and including 2.3.8. CSRF attacks exploit the trust a web application places in an authenticated user's browser by forcing the browser to make unwanted requests to the vulnerable application without the user's knowledge. The vulnerability does not require authentication to craft the malicious request, but successful exploitation requires a victim who is already logged in to the WordPress site and who visits or interacts with the attacker's crafted content. An attacker can achieve various impacts depending on the actions available through the vulnerable endpoints, ranging from data manipulation to administrative account compromise. The vulnerability has been patched in version 2.3.9 and later.
Affected products
- Mang Board Mang Board WP <=2.3.8
Timeline
- 2026-08-25: disclosed: Vulnerability reported by John Ryan Albon
- 2026-09-02: advisory: Published by Patchstack
- 2026-09-02: patched: Fixed in version 2.3.9