Security Advisory

CVE-2026-85349

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-16 06:00:14
Last updated 2026-09-17 12:36:32
Assigner WPScan
CVSS score 4.3
State PUBLISHED

Description

The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID.