MyBB Delete Account Plugin Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the MyBB Delete Account Plugin version 1.4. The issue arises in the account deletion reason input field, where attackers can inject malicious scripts. These scripts are executed in the admin interface when delete account reasons are viewed.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user viewing the delete account reasons in the admin interface.

Reproduction

To reproduce this vulnerability, navigate to the User Control Panel and select the option to delete an account. In the account deletion reason field, enter a script payload, such as a JavaScript alert. Once submitted, the injected script will execute when the admin views the delete account reasons.

Added: Jan 23, 2026, 5:30 PM
Updated: Jan 23, 2026, 10:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
6.3
remediation
0.0
relevance
2.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.