CVE-2026-78466: Fluent Boards Pro <= 2.0.11 - Authenticated (Subscriber+) Insecure Direct Object Reference
The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.11 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an authenticated WordPress account with at least Subscriber-level access. Unauthenticated visitors are not described as able to exploit it.
Which installations are affected?
Fluent Boards Pro versions up to and including 2.0.11 are affected. The provided data does not identify a safe fixed version.
What can an attacker do after exploiting the issue?
A qualifying authenticated attacker can perform an unauthorized action by abusing a user-controlled key that lacks validation. The specific action and affected objects are not identified in the available data.