Impact
Fluent Boards Pro versions up to 2.0.11 contain an IDOR flaw that permits a subscriber to access or retrieve information belonging to other users. The vulnerability arises because the plugin does not verify that the requesting actor owns or is authorized for the targeted resource before returning data. An attacker can exploit this to view task contents, project notes, or other private content that should be restricted to the owner.
Affected Systems
WordPress sites that run WP ManageNinja LLC’s Fluent Boards Pro plugin, specifically any installation using version 2.0.11 or earlier. Users of these older releases should verify the installed version and plan an upgrade.
Risk and Exploitability
The flaw has a CVSS score of 5.3, indicating moderate severity. EPSS data is not available, and the defect is not listed in CISA’s KEV catalog, implying no confirmed exploitation activity at present. Based on the description, the likely attack vector is a subscriber manipulating URLs or API parameters exposed by the plugin; no higher privileges are required beyond the standard subscriber role.
OpenCVE Enrichment