GHSA-7f4v-rw2p-hvrpMediumCVSS 4.3

The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when...

Published
September 16, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID.

🔗 References (3)