WordPress Plugin Vulnerabilities
FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR
Description
The plugin does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions and file attachments) of any other board on the site.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Diogo Pinto
Submitter
Diogo Pinto
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-20 (about 6 days ago)
Added
2026-07-20 (about 6 days ago)
Last Updated
2026-07-20 (about 6 days ago)