Impact
Editor Arbitrary File Deletion in Fluent Boards Pro versions up to 2.0.11 permits a user with editor privileges to delete any file located on the WordPress server. The vulnerability can cause unintended loss of content, configuration files, or critical assets, resulting in data loss or service disruption.
Affected Systems
WordPress sites that have installed the WP Manage Ninja: Fluent Boards Pro plugin, version 2.0.11 or earlier, are affected.
Risk and Exploitability
The CVSS rating of 6.8 indicates medium severity. No EPSS score is available and the issue is not listed in CISA’s KEV list. The attack is likely local and requires an authenticated user with editor privileges, but once authenticated, the deletion can target any file accessible by the web server process.
OpenCVE Enrichment