CVE-2026-86798
HootBoard <= 3.1.4 - Unauthenticated Stored XSS via Board Configuration REST Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a public page, allowing unauthenticated users to inject arbitrary web scripts that will execute in the browser of anyone visiting that page, including administrators.
| Vendor | unknown |
| Product | hootboard |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown hootboard
Be the first to know when new unknown vulnerabilities affecting unknown hootboard are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / HootBoard
0 ≤ 3.1.4
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan