Impact
The FluentBoards plugin for WordPress contains a missing authorization flaw that permits attackers to exploit incorrectly configured access control security settings. This weakness, identified as CWE-862, enables a user to view or modify sensitive board data and configuration beyond their intended permissions, potentially leading to data exposure or unauthorized content changes.
Affected Systems
All installations of the Mahmudul Hasan Arif FluentBoards plugin from the unspecified earliest release up to and including version 1.91.1 are affected. Users deploying these versions should verify the exact build and coordinate an update.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.4, indicating moderate severity, and an EPSS score of less than 1 %, suggesting a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog, further implying limited current exploitation activity. The likely attack vector is through a compromised or insufficiently privileged account that can manipulate plugin settings, underscoring the need for timely remediation.
OpenCVE Enrichment