Impact
The vulnerability is a persistent cross‑site scripting flaw located in the WordPress Fluent Boards Pro plugin versions up to and including 2.0.11. Because input supplied by users in the plugin’s interface is not properly sanitized, an attacker with a subscriber role can inject JavaScript that is later rendered on the front‑end. The flaw is classified as CWE‑79, indicating an unchecked user input that can lead to arbitrary script execution.
Affected Systems
This issue affects the WP Manage Ninja Fluent Boards Pro plugin for WordPress. All installations of the plugin with a version number 2.0.11 or earlier are vulnerable. Any WordPress site using this plugin and exposing its boards or related input areas to subscriber accounts is impacted.
Risk and Exploitability
The CVSS v3 base score of 6.5 denotes moderate severity. The EPSS score is not available, so a precise exploitation probability cannot be calculated. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a valid subscriber account; no higher privileges are needed. Once an attacker injects a payload through the plugin, other visitors who view the affected board experience the script execution, which could redirect them to external sites, display malicious content, or otherwise manipulate the front‑end.
OpenCVE Enrichment