Executive brief
Fluent Boards Pro is a WordPress plugin for collaborative project management and task tracking. An unauthenticated attacker can inject malicious PHP objects through the editor interface, allowing arbitrary code execution on the affected website. This poses a critical risk to website availability, customer data, and can lead to complete server compromise.
Technical details
The vulnerability is a PHP object injection flaw in Fluent Boards Pro versions up to 2.0.11, classified as an OWASP A3 Injection issue. The vulnerability requires the Editor privilege level to exploit, allowing attackers to manipulate how the site processes serialized data to execute arbitrary actions on the server. An attacker with editor privileges (or those who can bypass authentication to reach the editor) can instantiate malicious PHP objects and trigger remote code execution. The vulnerability has been patched in version 2.0.12 and later. Patchstack has released a mitigation rule to block attack attempts until sites are updated.
Affected products
- ManageNinja LLC Fluent Boards Pro <= 2.0.11
Timeline
- 2026-08-26: disclosed
- 2026-08-26: patched: Fixed in version 2.0.12