PT-2026-4518 · WordPress · Mybb Delete Account Plugin

0Xb9

·

Published

2026-01-23

·

Updated

2026-01-24

·

CVE-2021-47905

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MyBB Delete Account Plugin version 1.4
Description The MyBB Delete Account Plugin contains a cross-site scripting issue in the account deletion reason input field. An attacker can inject malicious scripts that will execute in the admin interface when viewing delete account reasons. The vulnerable input allows for the injection of scripts that impact the admin interface.
Recommendations Update the MyBB Delete Account Plugin to a newer version that addresses this issue. As a temporary workaround, sanitize all input to the account deletion reason field to prevent script injection.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47905

Affected Products

Mybb Delete Account Plugin