CVE-2026-89327: FluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by' Parameter
The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, including administrators.
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated FluentBoards board member can exploit it. The issue does not require administrator privileges, but a board member can make a comment appear to have been written by an administrator or another user.
What does an attacker need to do to exploit it?
The attacker must submit a comment while supplying a comment_by parameter that identifies a different user. The vulnerable plugin does not verify that the submitting board member matches the user named in that parameter.
Are comments from other users reliable evidence of authorship on affected sites?
No. On affected versions, a board member can spoof the apparent author of a comment, including an administrator, so comment attribution cannot be trusted.