The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-16 06:16
Updated : 2026-09-16 20:25
NVD link : CVE-2026-85349
Mitre link : CVE-2026-85349
CVE.ORG link : CVE-2026-85349
JSON object : View
Products Affected
No product.
CWE
No CWE.
