OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-86798 (CVSS 8.8)

NVD · officialPublished Oct 11, 2026Risk 37/100EPSS 0.2%

The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a public page, allowing unauthenticated users to inject arbitrary web scripts that will execute in the browser of anyone visiting that page, including administrators.

CVSS
8.8
AV:NetworkAC:LowPR:NoneUI:RequiredC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source