CVE-2026-78278: WordPress Fluent Boards Pro plugin <= 2.0.11 - Insecure Direct Object References (IDOR) vulnerability
Published Aug 24, 2026
·Updated
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
Affected Software
1 affected component
WordPress Fluent Boards Pro<=2.0.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Boards Proto a version that resolves this vulnerability.Fixed in 2.0.12
Event History
Aug 24, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The affected access level is Subscriber. The CVSS vector indicates the issue can be exploited remotely without privileges or user interaction.
2
What is the likely security impact?
The available severity data indicates low confidentiality impact, with no indicated integrity or availability impact. The scope is unchanged.
3
Which versions are affected?
Fluent Boards Pro versions 2.0.11 and earlier are identified as affected.