Executive brief
The kboard WordPress plugin is used to create and manage community discussion boards on WordPress sites. A flaw allows unauthenticated attackers to permanently delete media files uploaded to boards by guessing sequential file identifiers, resulting in data loss without authentication or verification of user permission.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) vulnerability in the board media deletion functionality. The plugin fails to verify ownership or proper authorization context before processing media deletion requests, allowing unauthenticated attackers to enumerate and delete arbitrary media by iterating numeric identifiers. The attack requires only network access to the WordPress installation and no prior authentication; an attacker can craft requests to delete media files directly and remove their database records. The vulnerability is fixed in version 6.7 and later.
Affected products
- WordPress.org kboard before 6.7
Timeline
- 2026-09-14: disclosed
- 2026-09-16: advisory