Impact
The FluentBoards WordPress plugin versions earlier than 2.0.15 fails to verify that the user submitting a comment is the same user specified in the ‘comment_by’ parameter. This flaw lets any board member craft comments that appear to be authored by another user, including site administrators. Such impersonation can be used to spread misinformation, mislead other users, or conduct covert manipulation of board discussions, potentially compromising the integrity of the collaboration environment.
Affected Systems
The vulnerability is limited to installations of the FluentBoards plugin for WordPress running any version older than 2.0.15. No other vendors or products are impacted.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. However, the flaw requires that the attacker already possesses a board member role, so it is an internal privilege escalation risk. Because it can subvert user identity, the potential impact on confidentiality and integrity of board content is significant, warranting prompt remediation.
OpenCVE Enrichment