CVE-2026-89328

NONE
Updated Sep 16, 2026
WordPress
Parameter Value
Affected Versions before 2.0.15
Vendor WordPress
Public PoC No

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board.