CVE-2026-78273: WordPress Fluent Boards Pro plugin <= 2.0.11 - Cross Site Scripting (XSS) vulnerability
Published Aug 27, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
Affected Software
1 affected component
wordpress/fluent-boards-pro<=2.0.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Boards Pro pluginto a version that resolves this vulnerability.Fixed in 2.0.12
Event History
Aug 27, 2026
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is exploitable by a user with Subscriber-level access. Exploitation also requires network access and user interaction.
2
What impact can successful exploitation have?
Successful exploitation may allow cross-site scripting with low impact to confidentiality, integrity, and availability. The scope is changed, meaning the vulnerable plugin can affect a security authority beyond its own scope.
3
Which versions should be considered affected?
Fluent Boards Pro versions up to and including 2.0.11 are identified as affected.