CVE-2026-75977

Mang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie

The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbw_get_hash_key() function that uses the current user's identity instead of the cookie username parameter when a WordPress user is logged in, combined with insufficient validation in mbw_validate_auth_cookie(). This makes it possible for authenticated attackers, with subscriber-level access and above, to forge administrator authentication cookies and change administrator passwords to achieve complete site takeover.


We have discovered 318 live websites that are affected by CVE-2026-75977.

Run a Free Instant Scan




Affected Software

Product  Mangboard
Category Wordpress Plugins
Vulnerable Domains318 live websites (100% of Mangboard install base)
Vulnerable Versions
  • from 0 through 2.3.7
Vulnerable Versions Count37 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-269 Improper Privilege Management



Details

  • Published - Aug 26, 2026
  • Updated - Aug 26, 2026

Credits

  • daroo (finder)

Website Distribution by Country

Number of websites using CVE-2026-75977
United States23 websites



Korea, South232 websites
Australia2 websites
Cyprus1 websites
GB1 websites
Singapore1 websites

Website Distribution by TLD

Number of websites using CVE-2026-75977
.com115 websites
.org16 websites
.net8 websites
.co1 websites
.co.uk1 websites
.com.au1 websites
.io1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-75977

Top websites that are affected by CVE-2026-75977. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Korea, South***,***
****.**.kr Korea, South*,***,***
***.**.kr Korea, South*,***,***
***********.**.kr Korea, South*,***,***
**********.kr Korea, South*,***,***
*****.net United States*,***,***
*******.com United States*,***,***
*****.**.kr Korea, South*,***,***
********.com Korea, South*,***,***
*****.com Korea, South*,***,***
See full domain list

FAQ

CVE-2026-75977 is Improper Privilege Management in Mangboard
A total of 318 websites have been identified as vulnerable to CVE-2026-75977, based on global website indexing conducted by WebTechSurvey.
The Mangboard is affected by the CVE-2026-75977 vulnerability.
Mangboard versions up to and including 2.3.7 are vulnerable to CVE-2026-75977.

References