MEDIUM
CVE-2026-88910
CVSS
5.3
Description
The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers.
Weakness (CWE)
CWE-639
Authorization Bypass (IDOR)
EPSS Score
0.24%
Probability of exploitation in next 30 days
15.3th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.