CVE-2026-89328: FluentBoards < 2.0.15 - Board Member+ Board Membership and Public Access Modification
The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/fluentboardsto a version that resolves this vulnerability.Fixed in 2.0.15 - Compensating control
Restrict board-management operations (adding/removing members and enabling public access to a private board) so they are only executable by users with board-manager privileges, not merely board membership, until the plugin is upgraded to 2.0.15.
Event History
Frequently Asked Questions
Who can exploit this issue?
Any user who is already a member of an affected FluentBoards board can exploit it. The issue does not require the user to have board-manager privileges.
What actions can an unauthorized board member perform?
A board member can perform manager-only board-management actions, including adding or removing board members and enabling public access for a private board.
Which plugin versions are affected?
FluentBoards versions earlier than 2.0.15 are affected. Version 2.0.15 is not described as affected.