🔐 CVE Alert

CVE-2026-86798

UNKNOWN 0.0

HootBoard <= 3.1.4 - Unauthenticated Stored XSS via Board Configuration REST Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a public page, allowing unauthenticated users to inject arbitrary web scripts that will execute in the browser of anyone visiting that page, including administrators.

Vendor unknown
Product hootboard
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown hootboard

Be the first to know when new unknown vulnerabilities affecting unknown hootboard are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / HootBoard
0 ≤ 3.1.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/a0cfbbb7-4cc5-4ec0-b420-e249204fcd46/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan