MEDIUM

CVE-2026-88910

2026-09-16 CVSS v3.1
CVSS
5.3

Description

The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers.

Weakness (CWE)

CWE-639 Authorization Bypass (IDOR)

EPSS Score

0.24%
Probability of exploitation in next 30 days
15.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE