CVE-2026-86798 PUBLISHED

HootBoard <= 3.1.4 - Unauthenticated Stored XSS via Board Configuration REST Endpoint

Assigner: WPScan
Reserved: 08.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a public page, allowing unauthenticated users to inject arbitrary web scripts that will execute in the browser of anyone visiting that page, including administrators.

Product Status

Vendor Unknown
Product HootBoard
Versions Default: unknown
  • affected from 0 to 3.1.4 (incl.)

Credits

  • Pablo González Pérez finder
  • Francisco José Ramírez Vicente finder
  • and Iñigo Sánchez Enciso finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE