CVE-2026-89331: FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Disclosure via Public Board Endpoints
The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FluentBoardsto a version that resolves this vulnerability.Fixed in 2.1.0
Event History
Frequently Asked Questions
Which deployments are exposed to this disclosure?
FluentBoards installations running versions before 2.1.0 are affected when they use the public, token-shared board feature. The exposed data is the email addresses of members on a shared board, which may include administrators.
What does an attacker need to retrieve member email addresses?
The issue can be exploited without authentication through the public endpoints for a token-shared board. The available information indicates the attacker needs access to such a shared board endpoint or its sharing token.
What is the immediate remediation?
Update FluentBoards to version 2.1.0 or later. If updating cannot occur immediately, avoid using the public, token-shared board feature for boards whose member email addresses must remain private.