CVE-2025-3435

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 79

Summary

CVE-2025-3435: The Mang Board WP plugin for WordPress, used in multi-site installations and where unfiltered_html has been disabled, is susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability, affecting versions up to 1.8.6, stems from insufficient input sanitization and output escaping of the board_header and board_footer parameters. Authenticated attackers with administrator-level access can exploit this weakness to inject malicious web scripts, which execute whenever a user accesses an injected page.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share