Description
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
Published: 2026-08-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Update
AI Analysis

Impact

Fluent Boards Pro versions up to 2.0.11 contain an IDOR flaw that permits a subscriber to access or retrieve information belonging to other users. The vulnerability arises because the plugin does not verify that the requesting actor owns or is authorized for the targeted resource before returning data. An attacker can exploit this to view task contents, project notes, or other private content that should be restricted to the owner.

Affected Systems

WordPress sites that run WP ManageNinja LLC’s Fluent Boards Pro plugin, specifically any installation using version 2.0.11 or earlier. Users of these older releases should verify the installed version and plan an upgrade.

Risk and Exploitability

The flaw has a CVSS score of 5.3, indicating moderate severity. EPSS data is not available, and the defect is not listed in CISA’s KEV catalog, implying no confirmed exploitation activity at present. Based on the description, the likely attack vector is a subscriber manipulating URLs or API parameters exposed by the plugin; no higher privileges are required beyond the standard subscriber role.

Generated by OpenCVE AI on August 24, 2026 at 12:51 UTC.

Remediation

Vendor Solution

Update the WordPress Fluent Boards Pro Plugin to the latest available version (at least 2.0.12).


OpenCVE Recommended Actions

  • Update the Fluent Boards Pro plugin to version 2.0.12 or later.
  • Where possible, limit subscriber role capabilities so they cannot reach the vulnerable endpoints.
  • Enforce server‑side input validation to confirm that requested resources belong to the authenticated user before returning data.

Generated by OpenCVE AI on August 24, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluent Forms
Vendors & Products Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluent Forms

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
Title WordPress Fluent Boards Pro plugin <= 2.0.11 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Wpmanageninja Fluent Forms
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T12:51:10.381Z

Reserved: 2026-08-24T07:38:04.147Z

Link: CVE-2026-78278

cve-icon Vulnrichment

Updated: 2026-08-24T12:49:59.412Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T12:16:55.507

Modified: 2026-08-24T16:40:53.647

Link: CVE-2026-78278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:45:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key