Executive brief
Fluent Boards Pro is a WordPress plugin used to create discussion boards and community forums. An authenticated user with the Editor role can upload arbitrary files to the web server, potentially allowing attackers to gain control of the website, access sensitive data, or inject malicious code. The vulnerability affects versions up to 2.0.11 and has been patched in version 2.0.12.
Technical details
The vulnerability is an arbitrary file upload weakness in the Fluent Boards Pro WordPress plugin that allows users with Editor privileges to bypass file upload restrictions and upload malicious files to the server. The root cause lies in insufficient validation or sanitization of uploaded files in the editor functionality. Exploitation requires Editor-level authentication but no additional user interaction. A successful exploit allows an attacker to upload webshells or other malicious code, leading to remote code execution and complete server compromise. The vulnerability is patched in version 2.0.12 and later; affected versions are 2.0.11 and below.
Affected products
- ManageNinja Fluent Boards Pro ≤ 2.0.11
Timeline
- 2026-08-26: disclosed
- 2026-08-27: advisory
- 2026-08-27: patched: Version 2.0.12 released