Junglewise Threat Intelligence

CVE-2026-78275: WP ManageNinja Fluent Boards Pro arbitrary file deletion

CVE-2026-78275 · Severity: medium · CVSS 6.8 · Published 2026-08-27

Technologies: WP ManageNinja Fluent Boards Pro. Vendors: WP ManageNinja.

Executive brief

Fluent Boards Pro is a WordPress plugin used to manage project boards and tasks on websites. A vulnerability in versions up to 2.0.11 allows users with the Editor role to delete arbitrary files from the server, potentially breaking the website and exposing sensitive data. This affects any WordPress site running the vulnerable plugin with Editor-level users.

Technical details

This vulnerability is classified as arbitrary file deletion with a broken access control root cause (OWASP A1). Users with Editor privilege level can exploit this flaw to delete files on the server without proper authorization checks. The vulnerability is network-accessible and requires only Editor-level authentication, making it exploitable by any user with that role. An attacker with Editor access can permanently delete critical website files, causing denial of service or data loss. The vulnerability is patched in version 2.0.12 and later.

Affected products

  • WP ManageNinja Fluent Boards Pro <=2.0.11

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: version 2.0.12

References

Related threats