CVE-2026-85349: FluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOR
The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID.
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including a Subscriber account that has no access to any FluentBoards board. The attacker must be able to reference the target user's user ID.
What information can be exposed?
An attacker can obtain the list of private FluentBoards boards that an arbitrary user belongs to. The issue is an information disclosure and the provided data does not indicate that it grants access to board contents.
Which versions are affected?
FluentBoards versions before 2.0.15 are affected. Updating to version 2.0.15 or later addresses the described authorization weakness.