Description
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
Published: 2026-08-27
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Editor Arbitrary File Deletion in Fluent Boards Pro versions up to 2.0.11 permits a user with editor privileges to delete any file located on the WordPress server. The vulnerability can cause unintended loss of content, configuration files, or critical assets, resulting in data loss or service disruption.

Affected Systems

WordPress sites that have installed the WP Manage Ninja: Fluent Boards Pro plugin, version 2.0.11 or earlier, are affected.

Risk and Exploitability

The CVSS rating of 6.8 indicates medium severity. No EPSS score is available and the issue is not listed in CISA’s KEV list. The attack is likely local and requires an authenticated user with editor privileges, but once authenticated, the deletion can target any file accessible by the web server process.

Generated by OpenCVE AI on August 27, 2026 at 10:24 UTC.

Remediation

Vendor Solution

Update the WordPress Fluent Boards Pro Plugin to the latest available version (at least 2.0.12).


OpenCVE Recommended Actions

  • Upgrade the Fluent Boards Pro plugin to version 2.0.12 or later.
  • Restrict plugin editor access by limiting editor privileges to administrators only.
  • Perform a backup of site files and database before applying the update to restore in case of accidental loss.

Generated by OpenCVE AI on August 27, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
Title WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-27T09:03:51.299Z

Reserved: 2026-08-24T07:37:56.725Z

Link: CVE-2026-78275

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T10:16:37.510

Modified: 2026-08-27T10:16:37.510

Link: CVE-2026-78275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T10:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')