---
id: CVE-2026-88910
title: >-
  The kboard WordPress plugin before 6.7 does not verify ownership or context
  before deleting board media, allowing unauthenticated attackers to permanently
  delete its uploaded media files and their database records by iterating
  identifiers.
summary: >-
  The kboard WordPress plugin before 6.7 does not verify ownership or context
  before deleting board media, allowing unauthenticated attackers to permanently
  delete its uploaded media files and their database records by iterating
  identifiers.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-639
product: kboard
affected:
  - kboard < 6.7
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:57.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88910'
references:
  - url: 'https://wpscan.com/vulnerability/96119ba5-4dcd-4aff-adf9-83f058c3dc6d/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T12:14:48.805453Z'
epss: 0.00304
epssPercentile: 0.20512
ingestedAt: '2026-09-16T06:51:06.257Z'
---

## Overview

The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
