CVE-2026-85349
FluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID.
| Vendor | unknown |
| Product | fluentboards |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown fluentboards
Be the first to know when new unknown vulnerabilities affecting unknown fluentboards are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / FluentBoards
0 < 2.0.15
References
Credits
Usama Arshad WPScan