GHSA-q8hc-f88v-p32pLowCVSS 3.8

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board...

Published
September 16, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board.

🔗 References (3)