CVE-2026-14938
FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions and file attachments) of any other board on the site.
| Vendor | unknown |
| Product | fluentboards |
| Published | Aug 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown fluentboards
Be the first to know when new unknown vulnerabilities affecting unknown fluentboards are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / FluentBoards
0 < 1.95.3
References
Credits
Diogo Pinto WPScan