CVE-2025-3435
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 79
Summary
CVE-2025-3435: The Mang Board WP plugin for WordPress, used in multi-site installations and where unfiltered_html has been disabled, is susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability, affecting versions up to 1.8.6, stems from insufficient input sanitization and output escaping of the board_header and board_footer parameters. Authenticated attackers with administrator-level access can exploit this weakness to inject malicious web scripts, which execute whenever a user accesses an injected page.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.