Pondol BBS
Pondol BBS has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Pondol BBS has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by hy30nq. Pondol BBS is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.1.42.
CVE-2025-49336Pondol BBS <= 1.1.8.4 - Authenticated (Editor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Pondol BBS
Author
pondol
This is general bbs(board) plugin. Skin selection function(you can make skin and add to Pondol BBS). Support Variable Types skin(General Board, Notice, Gallery) Adjusting accessing auth by user level. Attaching files and download it.(All type of files could be attached as you set files extension on back-end) Searching enable. Adjusting table width and alignment. Adjusting items listing number. Important notice can be shown at top of lists(this option will be shown only to administrator). Secret item enable (fuctionally if you set this option, that item will be read by administartor, item owner only). Translation If you create your own language pack or update the existing one, you can send the text in PO and MO files for Pondol and we’ll add it to the plugin. You can download the latest version of the program for work with PO and MO files Poedit. translate to ko_KR translate to he_IL, special thanks to gchaimke@gmeail.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C