CVE-2026-78274: WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Upload vulnerability
Published Aug 27, 2026
·Updated
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
Affected Software
1 affected component
WordPress Fluent Boards Pro<=2.0.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Boards Pro Pluginto a version that resolves this vulnerability.Fixed in 2.0.12
Event History
Aug 27, 2026
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Editor-level privileges in WordPress. The vulnerability does not require user interaction and can be exploited remotely by an authenticated Editor.
2
Which installations are affected?
Fluent Boards Pro versions 2.0.11 and earlier are affected. The provided information does not state whether any particular WordPress configuration or feature must be enabled.
3
What is the potential impact?
An Editor may be able to upload arbitrary files. The listed impact includes high confidentiality, integrity, and availability effects, with scope changed.