Executive brief
FluentBoards is a WordPress plugin for managing collaborative discussion boards. The plugin fails to verify that a board member submitting a comment is actually the user being credited as the comment author, allowing any board member to impersonate others—including administrators—when posting comments. This undermines content attribution and enables reputation damage or social engineering attacks.
Technical details
The vulnerability is a broken access control flaw (CWE-290) in the comment submission functionality. The plugin does not validate the 'comment_by' parameter, allowing an authenticated board member to forge the author field of comments they submit. Attack precondition is board member access; the attacker can then craft requests specifying any other user (including admins) as the comment author. The vulnerability affects versions before 2.0.15 and has been patched in 2.0.15.
Affected products
- FluentBoards FluentBoards before 2.0.15
Timeline
- 2026-09-14: disclosed
- 2026-09-15: patched: Version 2.0.15 available