Impact
The FluentBoards WordPress plugin versions earlier than 2.0.15 fails to verify that the user submitting a comment is the same user specified in the ‘comment_by’ parameter. This flaw lets any board member craft comments that appear to be authored by another user, including site administrators. Such impersonation can be used to spread misinformation, mislead other users, or conduct covert manipulation of board discussions, potentially compromising the integrity of the collaboration environment.
Affected Systems
The vulnerability is limited to installations of the FluentBoards plugin for WordPress running any version older than 2.0.15. No other vendors or products are impacted.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. The CVSS score of 3.8 reflects a moderate impact that mainly affects integrity through potential user impersonation. However, the flaw requires that the attacker already possess a board member role, making it an internal privilege escalation risk. Because it can subvert user identity, the potential impact on confidentiality and integrity of board content is significant, warranting prompt remediation.
OpenCVE Enrichment