Description
The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID.
Published: 2026-09-16
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure – private board memberships can be exposed to unauthorized subscribers
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an IDOR that allows an authenticated user, even with a low‑privilege Subscriber role, to retrieve the private board memberships of any other user by simply referencing that user's identifier. The plugin fails to enforce proper authorization checks, resulting in the disclosure of sensitive internal data such as private board memberships. This leakage can expose membership details and potentially facilitate social engineering or targeted attacks against board participants.

Affected Systems

WordPress sites use the FluentBoards plugin before version 2.0.15. The issue applies to all installations of this plugin that have not yet been updated to 2.0.15 or later, regardless of other configuration settings.

Risk and Exploitability

The EPSS score is lower than one percent, indicating a very low probability of exploitation in the current environment, and the vulnerability is not listed in the CISA KEV catalog. However, any authenticated user with a Subscriber account can trigger the disclosure by accessing the board‑listing endpoint with the target user’s identifier. The lack of strict authorization checks means that the attacker does not need elevated privileges; possession of a normal login is sufficient.

Generated by OpenCVE AI on September 20, 2026 at 05:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the FluentBoards plugin to version 2.0.15 or later on all WordPress installations.
  • If an immediate update is not possible, add a WordPress filter or custom code that blocks the board‑listing endpoint for users with the Subscriber role to prevent the IDOR from functioning as a workaround.
  • Regularly audit and reduce the number of active Subscriber accounts to limit the potential impact of any remaining unauthorised data exposure.

Generated by OpenCVE AI on September 20, 2026 at 05:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID.
Title FluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:36:32.590Z

Reserved: 2026-09-03T17:17:56.927Z

Link: CVE-2026-85349

cve-icon Vulnrichment

Updated: 2026-09-17T12:18:32.471Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:34.033

Modified: 2026-09-17T13:16:50.790

Link: CVE-2026-85349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:15:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor