CVE-2026-78276: WordPress Fluent Boards Pro plugin <= 2.0.11 - PHP Object Injection vulnerability
Published Aug 27, 2026
·Updated
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Affected Software
1 affected component
WordPress Fluent Boards Pro<=2.0.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Boards Pro pluginto a version that resolves this vulnerability.Fixed in 2.0.12
Event History
Aug 27, 2026
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs Editor-level privileges. The vulnerability does not require user interaction and can be exploited over the network.
2
What is the potential impact if exploitation succeeds?
Successful exploitation may compromise confidentiality, integrity, and availability, all rated High in the supplied CVSS vector.
3
Which plugin versions are affected?
Fluent Boards Pro versions 2.0.11 and earlier are identified as affected.