Description
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78278. Reason: This candidate is a reservation duplicate of CVE-2026-78278. Notes: All CVE users should reference CVE-2026-78278 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78278. Reason: This candidate is a reservation duplicate of CVE-2026-78278. Notes: All CVE users should reference CVE-2026-78278 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Fluent Boards Pro to a version newer than 2.0.11 to receive the vendor patch.
  • If an upgrade is not immediately possible, restrict Subscriber‑level users from accessing the vulnerable plugin endpoints by revoking or limiting the relevant capabilities in WordPress.
  • Audit the site’s logs for abnormal object key usage to detect potential exploitation attempts.

Generated by OpenCVE AI on August 25, 2026 at 06:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References

No reference.

History

Thu, 03 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Fluent Boars
Fluent Boars fluent Boards Pro
Wordpress
Wordpress wordpress
Vendors & Products Fluent Boars
Fluent Boars fluent Boards Pro
Wordpress
Wordpress wordpress

Wed, 26 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.11 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action. ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78278. Reason: This candidate is a reservation duplicate of CVE-2026-78278. Notes: All CVE users should reference CVE-2026-78278 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Title Fluent Boards Pro <= 2.0.11 - Authenticated (Subscriber+) Insecure Direct Object Reference

Tue, 25 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.11 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Title Fluent Boards Pro <= 2.0.11 - Authenticated (Subscriber+) Insecure Direct Object Reference
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Fluent Boars Fluent Boards Pro
Wordpress Wordpress
cve-icon MITRE

Status: REJECTED

Assigner: Wordfence

Published:

Updated: 2026-08-26T16:39:13.200Z

Reserved: 2026-08-24T16:32:17.654Z

Link: CVE-2026-78466

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Rejected

Published: 2026-08-25T06:19:00.227

Modified: 2026-09-03T05:13:15.143

Link: CVE-2026-78466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:38:14Z

Weaknesses

No weakness.