Executive brief
Fluent Boards Pro is a WordPress plugin used for building community discussion boards and managing user interactions. A flaw allows logged-in users with subscriber-level privileges to access and view other users' private data by manipulating object IDs in URLs, potentially exposing personal information and board content that should remain restricted.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) flaw in Fluent Boards Pro versions up to 2.0.11. The issue allows an authenticated attacker with subscriber-level access to access resources belonging to other users by modifying object identifiers in API requests or URLs. The attack requires valid plugin installation and an active subscriber account. An attacker can enumerate and retrieve unauthorized user data, posts, or other sensitive board content. The vulnerability has been patched in version 2.0.12.
Affected products
- WP ManageNinja Fluent Boards Pro ≤ 2.0.11
Timeline
- 2026-08-24: disclosed: Vulnerability published by Patchstack
- 2026-08-24: patched: Patched in version 2.0.12