WordPress Plugin Vulnerabilities
FluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by' Parameter
Description
The plugin does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, including administrators.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
SPOOFING
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
vuxvinh
Submitter
vuxvinh
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-14 (about 2 days ago)
Added
2026-09-14 (about 1 day ago)
Last Updated
2026-09-14 (about 1 day ago)